Is it true that the Linux Kernel has traditionally deprecated the idea of "security bugs"? I thought the kernel crew took the view that a bug is a bug.
So perhaps this policy is a kind of spoiler response to efforts to require all security bugs to have a CVE allocated.
Comments
Is it true that the Linux Kernel has traditionally deprecated the idea of "security bugs"? I thought the kernel crew took the view that a bug is a bug.
So perhaps this policy is a kind of spoiler response to efforts to require all security bugs to have a CVE allocated.