[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#782323: linux-image-3.16.0-4-amd64: setting net.ipv6.conf.all.accept_ra to 0 has no effect, thus does not protect against SLAAC attacks



On Wednesday, 1 June 2022 11:36:03 CEST Vincent Lefevre wrote:
> I may have an explanation of the issue (this would not be a kernel bug and
> the switch to systemd may have fixed it). There's an upstream related
> kernel bug
> 
> Now, with systemd, there is documentation at
> 
>   https://www.freedesktop.org/software/systemd/man/sysctl.d.html
> 
> which says in particular:
> 
>   The settings configured with sysctl.d files will be applied early
>   on boot. The network interface-specific options will also be
>   applied individually for each network interface as it shows up in
>   the system. (More specifically, net.ipv4.conf.*, net.ipv6.conf.*,
>   net.ipv4.neigh.* and net.ipv6.neigh.*).
> 
> So, if I understand correctly, the settings are now read much earlier,
> and normally before the network interfaces show up. Thus everything
> should now be fine.

Great that you found a (potential) proper fix. I hope it works for you :-)

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: