4 ms·
> The policy now will be that each kernel bug will get assigned a CVE. Do you have a citation for this? For a CNA to submit CVEs they need to submit a CVSS sc
by kayfox 3y ago
> The policy now will be that each kernel bug will get assigned a CVE.
Do you have a citation for this?
For a CNA to submit CVEs they need to submit a CVSS score, initially 100% of their scores will be audited, if the score is 0, it would be considered an invalidly assigned CVE. Issues assigned a CVE must be exploitable by someone who does not already have access to do the thing described, they also must have documented impact to the confidentiality, integrity or availability of the impacted system. All of this means Linux being a CNA should not result in an increase of CVEs in unless they are already not getting CVEs for those vulnerabilties.
- herczegzsolt 3y agohttps://lore.kernel.org/lkml/2024021314-unwelcome-shrill-690e@gregkh/ https://lore.kernel.org/lkml/2024021314-unwelcome-shrill-690... > Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify.
- NekkoDroid 3y agoI don't get how exactly they would be wrong with that and I am not sure why saying "update from the buggier version to a less buggier version" (that is implied with an assigned CVE) is a bad thing.