‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. drfloyd51 · · focus · HN ↗
    Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
    1. sippingabonedry · · focus · HN ↗
      Will everyone chill the F out for a minute?

      These get released every few weeks. Tons of CVEs. If a kernel developer farts in the forest, does anyone hear it?

      August saw separate Debian kernel updates released four days apart. Does anyone even reboot that often?

      I have three kernels installed over the last 45 days or so and I probably missed a few.

      1. nightfly · · focus · HN ↗
        I've been doing Linux sys-admin work for 10+ years. Used to be I could read the full report on what ever vulnerabilities came out and triage which servers needed to be updated now and which could wait. A few years ago notifications started having so many it would take more time/effort to read everything than it would to patch everything. With this notification there's even ten times more...
        1. Gigachad · · focus · HN ↗
          That's because the methodology changed in 2024

          >Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

          <a href="https:&#x2F;&#x2F;lwn.net&#x2F;Articles&#x2F;961961&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lwn.net&#x2F;Articles&#x2F;961961&#x2F;

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.