‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. john_strinlai · · focus · HN ↗
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

    &quot;number of cves&quot; is a useless metric, especially when it comes to the kernel.

    1. st_goliath · · focus · HN ↗
      &gt; _any_ bugfix is assigned a cve

      Any patch that is back ported to a stable kernel, indiscriminately. And they have also started assigning CVSS scores with the same kind of malicious compliance.

      Take for example, this patch in the device mapper RAID code:

      <a href="https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;kernel&#x2F;git&#x2F;torvalds&#x2F;linux.git&#x2F;commit&#x2F;?id=47f1441b281decde6954a2fa82b4131637d685ac" rel="nofollow">https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;kernel&#x2F;git&#x2F;torvalds&#x2F;lin...

      After back porting to stable, it got assigned CVE-2026-89558 (which is in this list), and a CVSS score of 9.8:

      <a href="https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;security&#x2F;vulns.git&#x2F;tree&#x2F;cve&#x2F;published&#x2F;2026&#x2F;CVE-2026-89558.cvss" rel="nofollow">https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;security&#x2F;vulns.git&#x2F;tree...

      Reasoning behind it being that theoretically, a RAID could be accessible over the network via NFS, iSCSI, etc... so if it gets corrupted, the buggy code path in the recovery (CVE-2026-89558) is effectively triggered over the network.

      1. marcosdumay · · focus · HN ↗
        There&#x27;s nothing malicious about the CVE. It lets people use it to index issues, like it was supposed to, and stops dumb people from using it as an indicator of work done or vulnerability level, things that it was never useful for.
        1. IshKebab · · focus · HN ↗
          Uhm I&#x27;m pretty sure a severity score is supposed to be a score of severity.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.