‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. thallium205 · · focus · HN ↗
    Pretty much any kernel bug gets a CVE by default now, right?
    1. wjholden · · focus · HN ↗
      Is that all there is here? The quantifier "several" did not prepare me for the wall of CVE numbers in this list.
      1. vdfs · · focus · HN ↗
        <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html states that because almost any kernel bug can potentially compromise system security, the CVE team acts with extreme caution and labels nearly all bug fixes with a CVE
    2. slopinthebag · · focus · HN ↗
      yes because the majority are memory safety issues, and it&#x27;s automatically assumed that a memory safety bug can lead to a vuln

      one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

      1. akersten · · focus · HN ↗
        &gt; perhaps c should get a __UNSAFE { } block,

        I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it

        1. slopinthebag · · focus · HN ↗
          in that case we need a block of system memory marked as unsafe so i can run these programs in it encapsulated

          perhaps we could call it a sedimentchest?

          1. catlifeonmars · · focus · HN ↗
            I think that’s just called “memory”. Encapsulation is your machine.
          2. someonebaggy · · focus · HN ↗
            See xkcd&#x27;s sandboxing cycle. They exist, they&#x27;re called processes
        2. branc116 · · focus · HN ↗
          cheap shot lol
      2. insanitybit · · focus · HN ↗
        No. It&#x27;s because Greg doesn&#x27;t like the CVE system and MITRE, the stupidest decision ever, made Greg a CNA, and this is his tantrum that he&#x27;s been waiting 40 years to throw.
      3. debugnik · · focus · HN ↗
        C has many more ways to trigger undefined behaviour than memory access. If C had unsafe blocks they&#x27;d restrict most forms of signed integer arithmetic and shifting, for a start.
    3. seba_dos1 · · focus · HN ↗
      Yes. It looks funny, but it&#x27;s a nothing burger.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.