‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. thallium205 · · focus · HN ↗
    Pretty much any kernel bug gets a CVE by default now, right?
    1. slopinthebag · · focus · HN ↗
      yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

      one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

      1. insanitybit · · focus · HN ↗
        No. It's because Greg doesn't like the CVE system and MITRE, the stupidest decision ever, made Greg a CNA, and this is his tantrum that he's been waiting 40 years to throw.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.