Post #3114967
2026-04-30 00:33 UTC
Replies (3)
-
@argv_minus_one@mastodon.sdf.org 2026-04-30 00:37
@warthog9@social.afront.org The kernel compile option that introduces the vulnerability seems to be either CONFIG_CRYPTO_USER_API_AEAD or CONFIG_CRYPTO_AEAD. I think. I dunno. Details are sketchy.
-
@warthog9@social.afront.org 2026-04-30 00:37
@argv_minus_one@mastodon.sdf.org nevermind, I need to go remind myself why I don't drink: root@erebor:/var/log# modinfo algif_aead name: algif_aead filename: (builtin) description: AEAD kernel crypto API user space interface author: Stephan Mueller license: GPL file: crypto/algif_aead root@erebor:/var/log#
-
@gregkh@social.kernel.org 2026-04-30 08:34
@warthog9@social.afront.org @argv_minus_one@mastodon.sdf.org I’d argue this not having a broader security push before the public release happened, is a pretty serious failure on someone’s part. And who is that “someone”? We fix bugs like this in the kernel on a daily basis. If people have not learned to constantly upgrade to stay ahead of this, then why even assign these 10 CVEs a day in the first place? :)