|
|
|
|
|
by marshray
51 days ago
|
|
The lesson here being... compile your own kernel from git sources every few days? Give up entirely on non-virtualized container security? This is not sarcasm. I'd finally given in and started learning about docker/podman-style OCI containerization last week. |
|
For immediate mitigation, block AF_ALG socket creation via seccomp or blacklist the algif_aead module: