v1.4.0
fix: align CVE-2026-43284 module list with vendor guidance
Swap xfrm_algo for ipcomp4/ipcomp6 per Red Hat, Ubuntu, and AWS recommendations. Blocking the framework module is over-broad; the ESP and IPComp protocol modules plus xfrm_user are sufficient.