<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in.]]></title><description><![CDATA[<p>Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle,  and Alma as the vulnerable code is built-in.</p>]]></description><link>https://board.circlewithadot.net/topic/324b468f-bd6b-46a2-89f6-c021afee3726/creating-a-separate-post-so-more-people-see-this-the-mitigation-recommended-by-theori.io-for-copy.fail-will-not-work-for-any-rhel-or-rhel-derived-distro-including-centos-fedora-oracle-and-alma-as-the-vulnerable-code-is-built-in.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 19:56:30 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/324b468f-bd6b-46a2-89f6-c021afee3726.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 22:43:58 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in. on Fri, 01 May 2026 11:29:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/idkrn%40infosec.exchange">@<span>idkrn</span></a></span> Sure, RBAC too, subjects with connect/bind rules automatically apply restrictions on socket families (limited to AF_UNIX/AF_INET).  Any use of other socket families above that requires explicit sock_allow_family rules, so would block the AF_ALG use.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116499084982442637</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116499084982442637</guid><dc:creator><![CDATA[grsecurity@infosec.exchange]]></dc:creator><pubDate>Fri, 01 May 2026 11:29:23 GMT</pubDate></item><item><title><![CDATA[Reply to Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in. on Thu, 30 Apr 2026 19:47:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/grsecurity%40infosec.exchange">@<span>grsecurity</span></a></span> you said grsec can be vulnerable “only MODHARDEN has a chance.” What about rbac?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/idkrn/statuses/116495381141407046</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/idkrn/statuses/116495381141407046</guid><dc:creator><![CDATA[idkrn@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 19:47:27 GMT</pubDate></item><item><title><![CDATA[Reply to Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in. on Thu, 30 Apr 2026 02:51:56 GMT]]></title><description><![CDATA[<p>For RHEL/RHEL-derived configurations, this approach will work (the function name has been stable since 2015 and initcall_blacklist has been supported since 2014): <a href="https://news.ycombinator.com/item?id=47956504" rel="nofollow noopener"><span>https://</span><span>news.ycombinator.com/item?id=4</span><span>7956504</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116491387957052804</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116491387957052804</guid><dc:creator><![CDATA[grsecurity@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 02:51:56 GMT</pubDate></item><item><title><![CDATA[Reply to Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in. on Wed, 29 Apr 2026 22:44:42 GMT]]></title><description><![CDATA[<p>For it to be effective at all, you would need to have CONFIG_CRYPTO_USER_API_AEAD=m.  If it's =y, there is no module and the mitigation is a no-op. <a href="https://oracle.github.io/kconfigs/?config=CRYPTO_USER_API_AEAD&amp;" rel="nofollow noopener"><span>https://</span><span>oracle.github.io/kconfigs/?con</span><span>fig=CRYPTO_USER_API_AEAD&amp;</span></a><br /> shows the setting for common distros/versions, but it's most reliable to check your running kernel's config.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116490415797976730</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/grsecurity/statuses/116490415797976730</guid><dc:creator><![CDATA[grsecurity@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 22:44:42 GMT</pubDate></item></channel></rss>