If your system works perfectly fine with the mitigations active, keep them. At the current state some kernels are fixed, but upstream is still adding newer fixes to 6.18+ and 7.x+ series. Older series may be more vulnerable …
7.x series has the latest fixes for these. Try it out. You can check modules one by one and read about them, if they are still affected. And regardless if your disk is not encrypted you can hack it with any Linux Live-Media anyway …
Nah i don’t use it, my plan was first to find out if my VPN is working as before… but as it looks it is no longer working.
Im wondering if this module blocks are still active in background or what is going on here… maybe it isn’t so easy to revert this changes from mitigation and there is more to do as deleting this files and restarting my device?
It sounds like he can’t activate the kill switch. Have you made any changes to your firewall (iptables/nftables), and have you checked the lock mode in your app/config?
1 month ago in early May it was running fine, i didn’t change much around my system but there was 2 Manjaro Distro Updates since then and this mitigation stuff which i executed.
I also removed maybe 6 orphan pakages few days ago.
What you mean with checked? I clicked there again to connect to a VPN but that message popped up again:
There is no available or enabled Network Lock mode, sorry.
I also just try to run my VPN also on my PC (where this mitigations are still active) but there is also this Network Lock mode info showing up.
The Kill Switch (Network Lock Mode) is a set of firewall rules. There may be an outdated rule getting in the way, or there might be a general issue with your firewall—perhaps a permission problem.
Aha. We now know what is it. Please correct me if i got it wrong.
To sum up, iptables gets phased out. It now (since 1-2 updates) runs pretty much as a compatibility module for the newer nft firewall. In theory the apps still relying on iptables should work but i guess there will be glitches here and there. I only tested QEMU cause it had problems in this regard before and it worked but i guess your vpn program didn’t.