<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[FFS again??]]></title><description><![CDATA[<p>FFS again?? <a href="https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo" rel="nofollow noopener"><span>https://</span><span>github.com/0xdeadbeefnetwork/C</span><span>opy_Fail2-Electric_Boogaloo</span></a></p><p>If you have a modular kernel, blocking loading of modules esp4 and esp6 (IPsec <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4a9.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--hankey" style="height:23px;width:auto;vertical-align:middle" title="💩" alt="💩" />) in modprobe.d config should mitigate.</p><p>Given that this is the second time, a system-global seccomp filter blocking all splice-type syscalls/syscall-flags would probably be safer.</p>]]></description><link>https://board.circlewithadot.net/topic/170af55e-b3c4-4148-97a0-dc87e528e374/ffs-again</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:15:28 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/170af55e-b3c4-4148-97a0-dc87e528e374.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 May 2026 20:13:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:45:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io" rel="nofollow noopener">@<span>dalias</span></a></span> <span><a href="/user/alwayscurious%40infosec.exchange" rel="nofollow noopener">@<span>alwayscurious</span></a></span> (by "normal users" I mean "people who haven't yet studied the arcane magicks of io_uring)</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/ska/statuses/116535244755472551</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/ska/statuses/116535244755472551</guid><dc:creator><![CDATA[ska@social.treehouse.systems]]></dc:creator><pubDate>Thu, 07 May 2026 20:45:18 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:44:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io" rel="nofollow noopener">@<span>dalias</span></a></span> <span><a href="/user/alwayscurious%40infosec.exchange" rel="nofollow noopener">@<span>alwayscurious</span></a></span> splice is the only zero-copy mechanism available to normal users. I would hate to disable it. I'd rather disable the kernel modules one by one (for now, only relatively obscure stuff has been revealed to be broken; this may change in the future).</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/ska/statuses/116535241897832319</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/ska/statuses/116535241897832319</guid><dc:creator><![CDATA[ska@social.treehouse.systems]]></dc:creator><pubDate>Thu, 07 May 2026 20:44:34 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:24:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/alwayscurious%40infosec.exchange">@<span>alwayscurious</span></a></span> Yes, if you're trying to run a business with millions of concurrent users efficiently rather than just paying AWS obscene amounts of money and passing on the cost to your customers.</p><p>For any ordinary desktop or server applications though? No, it's useless premature optimization, and now known to be extremely unsafe in how it's implemented.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535163611206349</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535163611206349</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Thu, 07 May 2026 20:24:39 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:22:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io" rel="nofollow noopener">@<span>dalias</span></a></span> Is splice even useful nowadays?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/alwayscurious/statuses/116535155012781531</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/alwayscurious/statuses/116535155012781531</guid><dc:creator><![CDATA[alwayscurious@infosec.exchange]]></dc:creator><pubDate>Thu, 07 May 2026 20:22:28 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:21:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/emma%40orbital.horse">@<span>emma</span></a></span> Yes, it's the same, and the mitigation is exactly what I was recommending.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535152527230808</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535152527230808</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Thu, 07 May 2026 20:21:50 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:20:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/emma%40orbital.horse">@<span>emma</span></a></span> Looking. I think this is the same vuln.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535147953269619</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116535147953269619</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Thu, 07 May 2026 20:20:40 GMT</pubDate></item><item><title><![CDATA[Reply to FFS again?? on Thu, 07 May 2026 20:16:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io">@<span>dalias</span></a></span> okay, I'm not a kernel person, should we be applying the mitigation described here, or something similar? <a href="https://github.com/V4bel/dirtyfrag" rel="nofollow noopener"><span>https://</span><span>github.com/V4bel/dirtyfrag</span><span></span></a> Or do I go back to MacOS until there's a fix?</p>]]></description><link>https://board.circlewithadot.net/post/https://orbital.horse/users/emma/statuses/116535131335938934</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://orbital.horse/users/emma/statuses/116535131335938934</guid><dc:creator><![CDATA[emma@orbital.horse]]></dc:creator><pubDate>Thu, 07 May 2026 20:16:27 GMT</pubDate></item></channel></rss>