‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. thallium205 · · focus · HN ↗
    Pretty much any kernel bug gets a CVE by default now, right?
    1. slopinthebag · · focus · HN ↗
      yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

      one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

      1. akersten · · focus · HN ↗
        > perhaps c should get a __UNSAFE { } block,

        I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it

        1. slopinthebag · · focus · HN ↗
          in that case we need a block of system memory marked as unsafe so i can run these programs in it encapsulated

          perhaps we could call it a sedimentchest?

          1. catlifeonmars · · focus · HN ↗
            I think that’s just called “memory”. Encapsulation is your machine.
          2. someonebaggy · · focus · HN ↗
            See xkcd's sandboxing cycle. They exist, they're called processes
        2. branc116 · · focus · HN ↗
          cheap shot lol
      2. insanitybit · · focus · HN ↗
        No. It's because Greg doesn't like the CVE system and MITRE, the stupidest decision ever, made Greg a CNA, and this is his tantrum that he's been waiting 40 years to throw.
      3. debugnik · · focus · HN ↗
        C has many more ways to trigger undefined behaviour than memory access. If C had unsafe blocks they'd restrict most forms of signed integer arithmetic and shifting, for a start.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.