u/Elbow2009

Dirty Frag and Surface Linux kernel 6.19.8-surface-3

Not sure if the latest Surface Linux kernel 6.19.8-surface-3 was updated to protect from the Dirty Frag vulnerability. I did update to it, but then my cameras stopped working (I had gotten them working in the 6.18.7-surface-1 kernel I'd been on). Fortunately everything else worked.

But I wanted the cameras to work after all the work I'd put into them so I went back to the previous kernel and went with blocking access to the vulnerable kernel modules (esp4, esp6, and rxrpc) by blacklisting them. Since it could impact any workloads relying on IPsec, I checked to make sure, but my Nord VPN is using the NordLynx protocol so I've lost no function there.

Anyone else dealing with Dirty Frag issues? I updated another PC to the latest Debian Bookworm kernel that was secure.

reddit.com
u/Elbow2009 — 3 days ago