We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent cd8f6c8 commit 275b583Copy full SHA for 275b583
build_debian.sh
@@ -272,6 +272,7 @@ check system $HOST
272
EOF
273
274
## Config sysctl
275
+## TODO: ipfrag* are for mitigating CVE-2018-5391, remove after kernel upgraded
276
sudo mkdir -p $FILESYSTEM_ROOT/var/core
277
sudo augtool --autosave "
278
set /files/etc/sysctl.conf/kernel.core_pattern '|/usr/bin/coredump-compress %e %t %p'
@@ -309,6 +310,9 @@ set /files/etc/sysctl.conf/net.ipv6.conf.eth0.accept_ra_defrtr 0
309
310
311
set /files/etc/sysctl.conf/net.core.rmem_max 2097152
312
set /files/etc/sysctl.conf/net.core.wmem_max 2097152
313
+
314
+set /files/etc/sysctl.conf/net.ipv4.ipfrag_high_thresh 262144
315
+set /files/etc/sysctl.conf/net.ipv4.ipfrag_low_thresh 196608
316
" -r $FILESYSTEM_ROOT
317
318
## docker-py is needed by Ansible docker module
0 commit comments