@erincandescent@akko.erincandescent.net
Post #2315118
2026-05-07 20:00 UTC
Because the responsible disclosure schedule and the embargo have been broken, no patch exists for any distribution. Use the following command to remove the modules in which the vulnerabilities occur.
sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; true"
but but but… I actually have ipsec tunnels :akko_cry:
RE: https://social.infinitespace.dev/@leona/statuses/01KR1Y7S7SYJ1E4VTMWF6J6NTG
Replies (3)
-
@jernej__s@infosec.exchange 2026-05-07 20:04
@erincandescent@akko.erincandescent.net Luckily mine are all on either pfSense or OpenWRT devices.
-
@raito@nixos.paris 2026-05-07 20:10
@erincandescent@akko.erincandescent.net you have to let go 😢
-
@lanodan@queer.hacktivis.me 2026-05-07 20:07
@erincandescent@akko.erincandescent.net Patch is available here: https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4