2 ms·
Greg and Linus do not believe in the entire concept of "vulnerabilities" in the Linux kernel and do not believe in the methods that distros use like cherry pick
by staticassertion 5mo ago
Greg and Linus do not believe in the entire concept of "vulnerabilities" in the Linux kernel and do not believe in the methods that distros use like cherry picking, therefor they typically are against issuing CVEs, scoring CVEs, describing vulnerabilities at all (if you use the word "vulnerability", your patch will be rejected), etc.
It's fundamentally their position to not work the way that you describe.
- baggy_trough 5mo agoThat doesn't really seem to map onto the situation since Greg himself released a 6.12 with the patch earlier today.
- staticassertion 5mo agoI don't know what you mean at all. I'm just repeating known kernel policy here. What does 6.12 have to do with anything?
- baggy_trough 5mo agoWhat is your interpretation of why Greg KH released a version of 6.12 with this fix in it today, other than to help distributions avoid this vulnerability?
- staticassertion 5mo agoWhy would he ever... not release a new version? I don't get what you're trying to say - I'm stating Greg's explicit policy on the topic. If he did something outside of that policy, that wouldn't change anything.
- baggy_trough 5mo agoIf he doesn't believe in the "concept of vulnerabilities" then it is remarkable that he released a 6.12 targeted on this one fix. Why would he do that otherwise?
- staticassertion 5mo agoSorry but he literally doesn't and nothing you say is going to change that he has explicitly stated that. This isn't up for debate, go ask him yourself, literally go to the first blog post on his site. As for the latest patch, Greg is currently being forced to clean up a big fucking mess by external parties. And he's miserable about it.
- Hendrikto 5mo agoI would like to read more about this. Do you have a source?
- staticassertion 5mo agohttp://www.kroah.com/log/blog/2026/02/16/linux-cve-assignment-process/ http://www.kroah.com/log/blog/2026/02/16/linux-cve-assignmen... I'd start with Greg's own words. You can probably find more on it from Spender/grsecurity's blog.
- SiempreViernes 5mo agoThe claims you make upthread are very hard to match with the text you link to, did you past the wrong URL?
- staticassertion 5mo agoNo, that's the correct URL.