Stupidity
Stupidity
Posted May 14, 2026 10:59 UTC (Thu) by madhatter (subscriber, #4665)In reply to: Stupidity by mirabilos
Parent article: Dirty Frag: a zero-day universal Linux LPE
If you mean "publish mitigations without the full explanation", I can't agree. In this case, the mitigations will be worse than the disease: on all my IPSec collapse points, for example, the mitigation would completely disable all my VPN links. Just telling me "do that" is, well, very disruptive, to say the least.
But when I have the full details, I can also see that the exploit requires an unprivileged user account. Since none of my collapse points have user accounts for anyone that isn't also a sysadmin with full sudo privileges, I know that I am no more exposed by this vulnerability than I was before it was discovered, and I can make a reasoned judgement about whether this justifies taking down all VPN links across the enterprise.
I do not think there is ever a justification for revealing less information than has elsewhere been revealed, merely in the hope that people won't find the elsewhere. If that wasn't what you were suggesting, then I apologise for getting the wrong end of the stick.
