logoalt Hacker News

john_strinlai • today at 1:01 AM • 4 replies • view on HN

note that _any_ bugfix is assigned a cve, which makes for big numbers.

>“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

https://docs.kernel.org/process/cve.html

"number of cves" is a useless metric, especially when it comes to the kernel.


Replies

SAI_Peregrinus • today at 1:12 AM

Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It's therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1/Low level vulnerability to CVSS v4.0.

If you're willing to stretch, missing but planned features also deny the use of said features since they haven't been added yet, and so are CVSS 1/Low vulnerabilities.

Resume-driven development for security researchers has never been easier!

➕ show 3 replies
mbreese • today at 2:16 AM

> note that _any_ bugfix is assigned a cve

I do find it interesting though, that in the interest of transparency, every bugfix gets a CVE. Which ends up being a huge number… which will ultimately yield a more insecure environment as we’re getting conditioned to ignore/discount CVEs by the volume.

Over-reporting in this case seems to risk being counterproductive.

➕ show 4 replies
rerdavies • today at 1:11 AM

With particular emphasis on "almost any bug might be exploitable".

➕ show 1 reply