logoalt Hacker News

john_strinlai • today at 4:06 AM • 0 replies • view on HN

severity on cve is a crapshoot most of the time, but especially with linux cna. i would not advise relying on them for decision making.

"We can not assign severity

[...]

So any group that attempts to give a “severity score” to a Linux CVE is lying to you, UNLESS they know exactly your use case.

ALWAYS ignore any attempt that groups such as NIST/NVD that purport to assign things like CVSS scores to a vulnerability. Those numbers are false and give companies a “fake sense of security”."

http://www.kroah.com/log/blog/2026/02/16/linux-cve-assignmen...