‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. thallium205 · · focus · HN ↗
    Pretty much any kernel bug gets a CVE by default now, right?
    1. slopinthebag · · focus · HN ↗
      yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

      one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

      1. debugnik · · focus · HN ↗
        C has many more ways to trigger undefined behaviour than memory access. If C had unsafe blocks they'd restrict most forms of signed integer arithmetic and shifting, for a start.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.