Tag
Hanno Böck discusses recent kernel exploits affecting the ESP (IPSEC) module and suggests disabling IPSEC-related kernel config options to reduce attack surface, highlighting how many unused kernel modules are loaded by default.