Several vulnerabilities have been discovered in the Linux kernel
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Several vulnerabilities have been discovered in the Linux kernel
Unofficial Hacker News client; not affiliated with Y Combinator.
john_strinlai · · focus · HN ↗
>“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”
<a href="https://docs.kernel.org/process/cve.html" rel="nofollow">https://docs.kernel.org/process/cve.html
"number of cves" is a useless metric, especially when it comes to the kernel.
rerdavies · · focus · HN ↗
SoftTalker · · focus · HN ↗
catlifeonmars · · focus · HN ↗
SoftTalker · · focus · HN ↗
odo1242 · · focus · HN ↗
rerdavies · · focus · HN ↗
:-P
whiskey-one · · focus · HN ↗
catlifeonmars · · focus · HN ↗
bigstrat2003 · · focus · HN ↗
PaulDavisThe1st · · focus · HN ↗
The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).
nananana9 · · focus · HN ↗
Much more agregiously you can design harmless a looking format that can run arbitrary code e.g. .doc with VBS. I have a very hard time blaming an user who falls for that even though MS puts up a scary looking popup.
GoblinSlayer · · focus · HN ↗
PowerElectronix · · focus · HN ↗