Post #2707393
2026-05-08 00:13 UTC
@hailey@hails.org If I wanted a big hammer to cut off this whole class of vuln without impacting important functionality, though, I'd just setup a global seccomp filter to block SYS_splice and related syscalls, or patch them out of the syscall table.
Replies (0)
No replies.