3 ms·
> The mainline kernel, as released by the Linux core team is up to date with security. Hold to account people that decided to skip patches as a matter of course
by typical182 7y ago
> The mainline kernel, as released by the Linux core team is up to date with security. Hold to account people that decided to skip patches as a matter of course
To me, the particulars of this exact case are not as interesting as the fact that the entire Linux patching and backporting of security issues seems _very_ fragile, with things frequently getting "lost" for mundane reasons, and a key part of the "why" it is so fragile is due to many of the core Linux development processes.
This particular CVE is apparently one small example that happened to catch some headlines out of _thousands_ of similar problems.
That talk linked above by Dmitry Vyukov is worthwhile for getting a sense of the magnitude of the problem.