[systemd-devel] VPN connections subject to hijack attack

Kenneth Porter shiva at sewingwitch.com
Fri Dec 6 09:51:03 UTC 2019


This affects all VPNs and is a consequence of using "loose" reverse path 
filtering for anti-spoofing.

Technical details:


According to the report, systemd changed the default to 2 in November 2018 
so many distros are vulnerable.


Here's Red Hat's explanation of why you might want to use a value of 2. 
"When RHEL has multiple IPs configured, only one is reachable from a remote 
network. Or why does RHEL ignore packets when the route for outbound 
traffic differs from the route of incoming traffic?"


More about what the rp_filter setting does:


[Please reply on the list. No need to cc me a copy.]

More information about the systemd-devel mailing list