‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. chrisjj · · focus · HN ↗
      &gt; Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.

      Er what?? CVEs should be assigned to bugs, not bugfixes, right?

      1. john_strinlai · · focus · HN ↗
        the whole process is talked about here (and the companion posts): <a href="http:&#x2F;&#x2F;www.kroah.com&#x2F;log&#x2F;blog&#x2F;2026&#x2F;02&#x2F;16&#x2F;linux-cve-assignment-process&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.kroah.com&#x2F;log&#x2F;blog&#x2F;2026&#x2F;02&#x2F;16&#x2F;linux-cve-assignmen...

        but no, in linux cve id is assigned &quot;on a one to two week delay from when the fix has landed in a released stable kernel version.&quot;

        1. chrisjj · · focus · HN ↗
          Thanks.

          &quot;While many security people love to argue what is, or is not, a vulnerability, while dealing with CVEs, a CNA must follow the definition that cve.org gives us which is:

          “An instance of one or more weaknesses in a Product that can be exploited, causing a negative impact to confidentiality, integrity, or availability; a set of conditions or behaviors that allows the violation of an explicit or implicit security policy.”

          So with that definition in mind, the kernel CNA team members look at every bugfix that is added to the stable kernel releases and reviews it to determine if it meets this criteria.&quot;

          So yes indeed, according to this, bugfixes are being examined for &quot;instance of one or more weaknesses in a Product that can be exploited&quot; - bugs.

          Oh dear, oh dear.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.