15 ms·
The linux kernel team disagrees with your approach but what do they know? > Note, due to the layer at which the Linux kernel is in a system, almost any bug mig
by bob001 2mo ago
The linux kernel team disagrees with your approach but what do they know?
> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.
- pixl97 2mo agoThat with LLMs being decent at chaining exploits suddenly very difficult issues can be accomplished by people with middling abilities and resources.
- alhirzel 2mo agoI was too busy waxing my armchair and didn't do any reading on the actual practices. Thank you for replying with this. It makes sense. I wonder if this level of purity will survive the test of time; since there are paid kernel developers, the situation could be very different from e.g. an entirely volunteer-maintained project.