Skip to content

Comment on We eliminated 1,400 CVEs in NanoClaw's container imagesparent

Comments

My favorite urgent must fix CVE from compliance was a bug in the Linux PCMCIA driver on some EC2 VMs.

I don’t say it’s the case there (it probably isn’t, you probably need hardware access or root), but sometimes those sorts of things do actually matter because there’s a way of causing them to be run anyway.

This is why it’s good to exclude things you don’t need. The less there is, the fewer places there are for problems to lurk.

Not against fixing it, but at the next normal update, it an emergency.

Why is that even part of the image?

It was a stock/default kernel setup, before my time.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.