TCP/IP stack vulnerabilities can be a real problem because the main defense is patching. There are no “unnecessary services” to disable, unless you choose not to run IPv6. From what I hear managers and CIOs in.gov,.mil, and elsewhere mostly think IPv6 brings “security” and other goodies; they are clearly not clued in to the problems on the horizon. I’m worried because the BSDs all use the same KAME IPv6 code.”]
Source: https://taosecurity.blogspot.com/2007/03/preview-of-ipv6-problems.html

