![]() Sine Nomine Associates: We are constantly minding the store for our customersWhen a Linux security alert is issued our teams expertise shines.
For the technical reader these notes will explain how a team digs in. This class of bug is related to the low level "struct sk_buff" buffer management data structures The OpenAFS kernel module as designed does not have access to that layer of buffer management, rather it uses the regular socket APIs for network traffic. We also had to consider what happens when people start implementing the several recommended remediation fixes to mitigate the problem in other software. The recommended mitigation steps involve disabling the `esp4`, `esp6`, and `rxrpc` kernel modules. These actions will not negatively impact the functionality of the OpenAFS kernel module. The bugs disclosed today look to be more of the same issues as the recent "Copy Fail" issues, which also affected the kernel socket buffer management. You keep your team working and we will keep minding the store for you. https://www.sinenomine.net End
|