‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. drfloyd51 · · focus · HN ↗
    Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
    1. sippingabonedry · · focus · HN ↗
      Will everyone chill the F out for a minute?

      These get released every few weeks. Tons of CVEs. If a kernel developer farts in the forest, does anyone hear it?

      August saw separate Debian kernel updates released four days apart. Does anyone even reboot that often?

      I have three kernels installed over the last 45 days or so and I probably missed a few.

      1. SoftTalker · · focus · HN ↗
        We're considering weekly reboots at work now with the pace of kernel updates coming out, and the speed with which vulnerabilities are getting exploited.
        1. sippingabonedry · · focus · HN ↗
          There is exactly one CVE in the entire list that is high severity, and it affects an obscure IBM NIC driver for big iron systems used in companies with more money than brains.

          You can skip the Xanax this week.

          1. Gigachad · · focus · HN ↗
            Problem is it takes more effort to read the CVE list and work out if you have one of the drivers impacted loaded than it does to just update the kernel.
            1. sippingabonedry · · focus · HN ↗
              Sorry but I'm not causing outages and rebooting systems every four days because the people whose job it is to do this can't triage properly. They are actively making other's lives more difficult. There's like 100 CVEs in that list and not a one of them is important to most systems. Even worse, if there was 1/100 it's a needle in a haystack.
              1. Gigachad · · focus · HN ↗
                If your system goes down to update a kernel then you have a major issue already. This is like manually renewing https certs. When the task is done often enough you just automate it in a painless way.
                1. sippingabonedry · · focus · HN ↗
                  There is more to the real world than running webshit behind VM clusters.

                  Real businesses still run legacy file/print services, license daemons, proprietary applications. Some still run on bare metal.

                  You need outage windows. You can't just YOLO it and update prod during the day, it's unbelieveably irresponsible.

                  1. anal_reactor · · focus · HN ↗
                    Well then, it's a business decision to accept the risks. IMO it makes sense that a percentage of machines would always be offline for maintenance. If you're running bare metal and you cannot afford 10% of your machines being offline at most times, then you're in deep shit if there's even a tiny traffic irregularity, and it's a sign that your management is YOLOing the company. Not uncommon though.
          2. john_strinlai · · focus · HN ↗
            severity on cve is a crapshoot most of the time, but especially with linux cna. i would not advise relying on them for decision making.

            "We can not assign severity

            [...]

            So any group that attempts to give a “severity score” to a Linux CVE is lying to you, UNLESS they know exactly your use case.

            ALWAYS ignore any attempt that groups such as NIST/NVD that purport to assign things like CVSS scores to a vulnerability. Those numbers are false and give companies a “fake sense of security”."

            <a href="http:&#x2F;&#x2F;www.kroah.com&#x2F;log&#x2F;blog&#x2F;2026&#x2F;02&#x2F;16&#x2F;linux-cve-assignment-process&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.kroah.com&#x2F;log&#x2F;blog&#x2F;2026&#x2F;02&#x2F;16&#x2F;linux-cve-assignmen...

        2. seany · · focus · HN ↗
          Weekly? 12 or 24hr cadence for upgrades isn&#x27;t that crazy in some places for cluster hosts...
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.