Skip to content

Comment on Over 400 Linux CVEs published in the last 24 hours alone

Comments

I guess very few around here remember the minor fuzz about this from a few years ago? The Linux Kernel Project became their own CNA (CVE Numbering Authority). A CVE is now slapped onto practically every bug fix that is back ported to a stable kernel, resulting in a flood of CVEs.

A blog post about this, published at the time: https://sigma-star.at/blog/2024/03/linux-kernel-cna/

The title is editorialized (i.e. the OP made it up), the link simply goes to the kernel CVE mailing list archive.

It's malicious-compliance CVE filing. Other interesting coverage of the issue by Risky Biz, https://news.risky.biz/risky-biz-news-the-linux-cna-mess/.

Given the broken nature of the CVE process, see for example Daniel Stenberg of cURL fame's frequent comments on this, I'm undecided whether this is a good thing, a bad thing, or a bit of both.

(Email the mods to clear up the editorial title problem; footer contact link.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.