‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. SAI_Peregrinus · · focus · HN ↗
      Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It&#x27;s therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1&#x2F;Low level vulnerability to CVSS v4.0.

      If you&#x27;re willing to stretch, missing but planned features also deny the use of said features since they haven&#x27;t been added yet, and so are CVSS 1&#x2F;Low vulnerabilities.

      Resume-driven development for security researchers has never been easier!

      1. viraptor · · focus · HN ↗
        &gt; It&#x27;s therefore a denial of service

        That doesn&#x27;t follow. In the extremely simple example, an adding service returning 1+1=3 has a bug, but it&#x27;s not a possible DoS situation at all.

        &gt; missing but planned features also deny the use of said features

        That&#x27;s not what DoS is.

        This whole situation with CVE assigning comes from the whole process being far from ideal. But it doesn&#x27;t mean it&#x27;s completely useless and doesn&#x27;t follow any rules at all.

        1. Gigachad · · focus · HN ↗
          &gt;but it&#x27;s not a possible DoS situation at all.

          Until someone finds there is a user input they can trigger this bug causing some other bit of code to read data from the wrong offset and now it&#x27;s a whole exploit.

          1. viraptor · · focus · HN ↗
            That&#x27;s an issue in the other code, not in the addition service. It would be lumped together if it was an addition function close to the other code. But I wrote service there on purpose.
            1. someonebaggy · · focus · HN ↗
              Why couldn&#x27;t a crash caused by filesystem corruption caused by a + operator that says 1+1=3 be filed as a DoS?
              1. tsimionescu · · focus · HN ↗
                It could. But it&#x27;s a CVE in the system that crashed or in the filesystem, not in the calculator web service that we were discussing. If a filesystem decides to use a bad online calculator for its internal logic, that&#x27;s a vulnerability on the filesystem, not the calculator.
                1. asdfaoeu · · focus · HN ↗
                  We aren&#x27;t talking about a calculator web service though we are talking about the Linux kernel and if there&#x27;s a bug in the kernel that could conceivably cause a crash in an otherwise correctly written application then that would be a CVE in the kernel.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.