Recent Kernel exploits, attack surface reduction, example IPSEC
Summary
The article discusses recent Linux kernel exploits targeting the esp module used in IPSEC, advocates attack surface reduction by disabling unused IPSEC-related kernel options, and suggests packaging strategies to minimize risk from unneeded modules.