Elektrine lite

← Feed

@warthog9@social.afront.org

Post #3114967

2026-04-30 00:33 UTC

@argv_minus_one@mastodon.sdf.org I was just commenting something similar that the advisory seems to be wackadoodle in another venue. I'd argue this not having a broader security push before the public release happened, is a pretty serious failure on someone's part. I'm back-tracking if ELs are even at risk, because I can't find the module but I haven't confirmed if it's just compiled in and not a module now 😕 (I've seen notes they are, I just want to confirm before I just table flip and move to elrepo's mainline kernels to get around this)

Replies (3)

  • @warthog9@social.afront.org The kernel compile option that introduces the vulnerability seems to be either CONFIG_CRYPTO_USER_API_AEAD or CONFIG_CRYPTO_AEAD. I think. I dunno. Details are sketchy.

    Open ##3114968

  • @warthog9@social.afront.org 2026-04-30 00:37

    @argv_minus_one@mastodon.sdf.org nevermind, I need to go remind myself why I don't drink: root@erebor:/var/log# modinfo algif_aead name: algif_aead filename: (builtin) description: AEAD kernel crypto API user space interface author: Stephan Mueller license: GPL file: crypto/algif_aead root@erebor:/var/log#

    Open ##3114970

  • @gregkh@social.kernel.org 2026-04-30 08:34

    @warthog9@social.afront.org @argv_minus_one@mastodon.sdf.org I’d argue this not having a broader security push before the public release happened, is a pretty serious failure on someone’s part. And who is that “someone”? We fix bugs like this in the kernel on a daily basis. If people have not learned to constantly upgrade to stay ahead of this, then why even assign these 10 CVEs a day in the first place? :)

    Open ##3114971