‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. rerdavies · · focus · HN ↗
      With particular emphasis on &quot;almost any bug might be exploitable&quot;.
      1. SoftTalker · · focus · HN ↗
        Even a bug-free program might be exploitable.
        1. catlifeonmars · · focus · HN ↗
          That sounds like a bug
          1. SoftTalker · · focus · HN ↗
            There are programs like sudo whose entire reason for existing is to enable privilege escalation. If you can find a way to make a user &quot;sudo&quot; something, that&#x27;s an exploit, but it&#x27;s not a bug in the program.
            1. odo1242 · · focus · HN ↗
              At that point you&#x27;re exploiting the user, who is not a bug-free program
              1. rerdavies · · focus · HN ↗
                Remove user and press any key to continue.

                :-P

                1. whiskey-one · · focus · HN ↗
                  Indeed, the user is the hardest part of the program to secure.
            2. catlifeonmars · · focus · HN ↗
              But if you squint, it might be a bug in the system to allow access to that program.
            3. bigstrat2003 · · focus · HN ↗
              That&#x27;s also not exploiting the program, it&#x27;s exploiting the user.
            4. PaulDavisThe1st · · focus · HN ↗
              Alternatively, consider any program which loads dynamic shared libraries (called &quot;plugins&quot; in many contexts). The program itself might be bug free; any plugin that is loaded will run (typically) with the full priviledges and access of the program (and thus likely the user).

              The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).

              1. nananana9 · · focus · HN ↗
                At least with plugins most people have a general notion that they run some sort of code as they provide some new functionality.

                Much more agregiously you can design harmless a looking format that can run arbitrary code e.g. .doc with VBS. I have a very hard time blaming an user who falls for that even though MS puts up a scary looking popup.

            5. GoblinSlayer · · focus · HN ↗
              Nope, sudo is safer, the alternative is running everything as root.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.