‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. mbreese · · focus · HN ↗
      &gt; note that _any_ bugfix is assigned a cve

      I do find it interesting though, that in the interest of transparency, every bugfix gets a CVE. Which ends up being a huge number… which will ultimately yield a more insecure environment as we’re getting conditioned to ignore&#x2F;discount CVEs by the volume.

      Over-reporting in this case seems to risk being counterproductive.

      1. Gigachad · · focus · HN ↗
        Depends on the end consumers stance on security. I&#x27;ve watched it shift from &quot;Only update if we can prove we are impacted&quot; to &quot;Update everything immediately just in case&quot;.

        The frequency and severity of cyber attacks has increased to the point a much more cautious approach has become common. It&#x27;s also easier to sell this work to management when you can point at the security tab on some tool and say &quot;Look we need to patch these CVEs&quot;

        1. autoexec · · focus · HN ↗
          &quot;Update everything immediately just in case&quot; is a lot less attractive when you see more downtime from updates breaking things than you do from hackers. Windows updates are an endless source of pain, but now every program seems to demand to be updated practically daily. Even things that you shouldn&#x27;t have to think about like keyboards, mice, and printers beg to be updated all the time.
          1. Gigachad · · focus · HN ↗
            Downtime is annoying but workable. You can&#x27;t unleak customer data after your system gets hacked.
            1. 1718627440 · · focus · HN ↗
              There is no reason, why a newer version has less bugs, than an older version. Both are essentially an unknown number. The only thing you know, is that you likely know a higher percentage of bugs for the older than for the newer version.
              1. Gigachad · · focus · HN ↗
                It certainly has less known bugs. And when you have to make a statement to the media, “we were hacked by an undiscovered 0 day exploit” sounds a lot better than “we were hacked by a known exploit because we didn’t update”
                1. fwip · · focus · HN ↗
                  &gt; It certainly has less known bugs.

                  This isn&#x27;t necessarily true, and will be less true in the coming age of LLM-automated vulnerability scanning. The version that you&#x27;re downloading (after being nagged for a day) that adds Feature A may contain 3 vulnerabilities that are already known before you even download the update, and may or may not fix old vulnerabilities.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.