‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. mbreese · · focus · HN ↗
      &gt; note that _any_ bugfix is assigned a cve

      I do find it interesting though, that in the interest of transparency, every bugfix gets a CVE. Which ends up being a huge number… which will ultimately yield a more insecure environment as we’re getting conditioned to ignore&#x2F;discount CVEs by the volume.

      Over-reporting in this case seems to risk being counterproductive.

      1. socializer · · focus · HN ↗
        It&#x27;s not very interesting. Linus, and by extension the Linux kernel, long had a dismissive attitude toward security research. This is basically a childish swing from one extreme (nothing gets a CVE) to another (everything gets a CVE).

        Kernel development is well-funded, both via grants and by direct employment at big tech companies, and if they wanted to properly triage and annotate vulnerabilities, and provide reasonable assessments of what is or isn&#x27;t likely to be a security risk, they absolutely could. They almost certainly could go to Google and say &quot;we need two people full-time on your payroll for this&quot; and they would get it.

        I don&#x27;t want to dunk on them too much because they&#x27;re generally doing God&#x27;s work, but these absolutist security stances are not worth being taken seriously.

        It&#x27;s basically saying that they can&#x27;t possibly provide a valuable service for 99.999% of the install base because there might a hypothetical person out there using Linux in a really weird way. If Microsoft tried to make an argument like that, they&#x27;d get crucified.

        1. serbuvlad · · focus · HN ↗
          I don&#x27;t think that Linus is dismissive of security, it is that he is very much a proponent of always rolling to the latest stable release.

          Linux only ever wanted to promise support for the latest release and even Linux LTS is a concession.

          And CVEs are basically a useless concept if you roll. (or at least not any more useful than any other bug tracker which supports tags)

          1. LtWorf · · focus · HN ↗
            &gt; Linux only ever wanted to promise support for the latest release and even Linux LTS is a concession.

            If he kept true of his &quot;we don&#x27;t break user space&quot; instead of it being &quot;we don&#x27;t break user space until we do and then it&#x27;s on you to deal with it&quot; perhaps more people would be willing to run the latest release.

            1. serbuvlad · · focus · HN ↗
              I have had way more issues provoked on RHEL-compatibles by RHEL&#x27;s Frankenstein backporty kernel than I ever have on Arch or Nix by the latest stable kernel.

              Linux LTS is much more about proprietary drivers targeting a stable internal kernel API&#x2F;ABI than about anything else.

              1. LtWorf · · focus · HN ↗
                I mean… good for you. How does that help me when my software crashes because they changed some API?
                1. doublepg23 · · focus · HN ↗
                  What user space APIs have they been routinely breaking?
                  1. throwaway7356 · · focus · HN ↗
                    The ones to manage IP filtering rules for example. Those APIs are even security-critical.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.