Comment on Linux kernel use-after-free in Netfilter, local privilege escalationparentComments−j_walter3yOnce they issue the patch...it's only a matter of time till a good chunk of reasonably decent coders can develop the exploit. Once the premise is released...yeah the top exploit coders will have this in a few hours.−hsbauauvhabzb3ySo we lower the bar to all adversaries with no benefit?If you can read exploit code to determine if patching is worth it for your use case, you can probably also read diffs for the same outcome.I’m not saying don’t release them, but releasing them with short notice seems irresponsible, without much benefit to defenders.
Comments
Once they issue the patch...it's only a matter of time till a good chunk of reasonably decent coders can develop the exploit. Once the premise is released...yeah the top exploit coders will have this in a few hours.
So we lower the bar to all adversaries with no benefit?
If you can read exploit code to determine if patching is worth it for your use case, you can probably also read diffs for the same outcome.
I’m not saying don’t release them, but releasing them with short notice seems irresponsible, without much benefit to defenders.