Dirty Frag: Universal Linux LPE
Dirty Frag: Universal Linux LPE
@devopscats
Do not apply on hosts which need IPsec.
Workarounds:
1️⃣ Try to migrate away from #IPsec to #Wireguard (quite some work per setup)
2️⃣ Use #SELinux to limit what "normal" processes can do with the modules (even more work, but probably only needs to be done once)
3️⃣ If none of this works, secure and minitor these machines, especially preventing untrusted users or code