4 ms·
This is the really concerning part. silently fixed in the upstream git is not at all an acceptable way to deal with serious security flaws in your product.
by KuiN 10y ago
This is the really concerning part. silently fixed in the upstream git is not at all an acceptable way to deal with serious security flaws in your product.
- grhmc 10y agoThis is frequently how the linux kernel operates.
- ungamed 10y agoThe distro vendors are the ones who frequently pull apart commit logs to be documented.
- sounds 10y agoIt is not done silently - lack of a public announcement is not the same thing as radio silence. (For CVEs affecting the linux kernel)
- gshulegaard 10y agoJust to be clear, systemd is not part of the Linux kernel. Also, if you are going to make a broad claim like that I would appreciate some citations/examples. I have no idea if you are wrong or right on the whole, but without examples I can't learn myself.
- kuschku 10y agoSee for example here: https://news.ycombinator.com/item?id=13472329 https://news.ycombinator.com/item?id=13472329
- kasabali 10y ago> if you are going to make a broad claim like that I would appreciate some citations/examples It's a common knowledge for people who are familiar with linux kernel development procedures. For starters you can search for two examples off the top of my head, "dirt cow" , "masturbating monkeys" or gregkh tty vulnerability. I'm sure you'll find dozens of other examples if you are sincere in your interest.