Comment mitigation while keeping ipsec functional (Score 1) 44
blacklisting the rpc module and disabling user namespaces seem to block the exploit on older kernels without having to blacklist ipsec modules according to my limited testing, YMMV. it probably breaks eg. rootless docker user mapping so there is a tradeoff