2026-05-02 14:41 UTC
@phnt@fluffytail.org @icon_of_computational_sin@mstdn.starnix.network @mangeurdenuage@shitposter.world
To me CopyFail revealed what a complete and utter clusterfuck modern Linux systems are — and it's not about the fact that vulnerabilities exists or how they are disclosed.
Cryptographic routines running in kernel space exported to user space via a socket, what the fuck for? For a 0.1% performance gain?!
And kernel module getting loaded when a user — any user at all, creates a socket of a particular type? For real?! This is the shit a ni~ ehm… user gets to deal with now?!
And in RHEL AFAIK they went even further and built that module right into the kernel — so there is nothing to unload or prevent from getting loaded.
Neither of these things should be possible in a system that is considered even remotely secure! :marseytabletired2:
While security folk insist on putting everything in a container — these things exist!
Replies (1)
-
@phnt@fluffytail.org 2026-05-02 15:04
@m0xEE@breloma.m0xee.net @icon_of_computational_sin@mstdn.starnix.network @mangeurdenuage@shitposter.world >To me CopyFail revealed what a complete and utter clusterfuck modern Linux systems are Have been for a very long time now. >And in RHEL AFAIK they went even further and built that module right into the kernel — so there is nothing to unload or prevent from getting loaded. initcall_blacklist=af_alg_init kills it.