Post #2707390
2026-05-07 23:39 UTC
@dalias@hachyderm.io oh wait no, I've got it mixed up. I think you're right
Replies (1)
-
@hailey@hails.org 2026-05-07 23:49
@dalias@hachyderm.io hold up, I see the iproute2 shell out. I disagree, I think AF_NETLINK is quite relevant. If you block that address family, you block the exploit. Most programs have no need for that address family, so it's unnecessary exposure. I'll revise my position when I see a poc which does not use AF_NETLINK