Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Since the exploit can be mitigated by simply blacklisting the AF_ALG module, why didn’t they release an advisory to disable the problematic module (which AFAIU is hardly used), and then only later, say after a week, release the patch for it? At least then you would have the immediate ability for a mitigation without giving away exactly how to exploit the bug.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: