| ▲ | marshray 3 hours ago | ||||||||||||||||||||||
The lesson here being... compile your own kernel from git sources every few days? Give up entirely on non-virtualized container security? This is not sarcasm. I'd finally given in and started learning about docker/podman-style OCI containerization last week. | |||||||||||||||||||||||
| ▲ | john_strinlai 3 hours ago | parent [-] | ||||||||||||||||||||||
in this specific case, they offer an alternative mitigation if your chosen distro has not updated yet: For immediate mitigation, block AF_ALG socket creation via seccomp or blacklist the algif_aead module: | |||||||||||||||||||||||
| |||||||||||||||||||||||