Skip to content

Comment on Dear Linux Kernel CNA, what have you done?

Comments

> Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify

Shouldn't this strategy lead to the opposite? By being overly cautious they should only assign CVEs for real demonstrable security issues.

You can think of it as a "fail-safe" situation.

Being cautious here means "it's better to assign a CVE when it's not a vulnerability, than to NOT assign a CVE when it's actually a vulnerability"

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.