Arthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 4 days agoSeveral vulnerabilitieslemmy.mlimagemessage-square43fedilinkarrow-up1378arrow-down14
arrow-up1374arrow-down1imageSeveral vulnerabilitieslemmy.mlArthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 4 days agomessage-square43fedilink
minus-squareslazer2au@lemmy.worldlinkfedilinkEnglisharrow-up104·4 days agoBut how many of those are actual problems though?
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up105arrow-down1·4 days agoTo add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
minus-squareslazer2au@lemmy.worldlinkfedilinkEnglisharrow-up37arrow-down2·4 days agoBut there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up25arrow-down1·4 days agoYes, hence why you would have to check the CVSS of all of those.
minus-squareklankin@piefed.calinkfedilinkEnglisharrow-up14·4 days agoAnd they just changed the CVE rules to include non-exploitable bugs too. My theory is its to pump AI ‘discoveries’ numbers
minus-squareAnAmericanPotato@programming.devlinkfedilinkEnglisharrow-up64·4 days agoMost of them are just crashing bugs. Worth fixing but you don’t need to panic. If anyone exploits them, then A) you’ll know about it, and B) they won’t get away with anything sensitive.
minus-squarebobtimus_prime@feddit.orglinkfedilinkarrow-up73·4 days agoNo need to panic? Tell that the kernel! :D
minus-squareSeductiveTortoise@piefed.sociallinkfedilinkEnglisharrow-up5·4 days agoThe kernel is really anxious though, panics all the time.
minus-squaresmeenz@lemmy.nzlinkfedilinkarrow-up6·3 days agoBut crashing bugs are good for denial of service.
But how many of those are actual problems though?
To add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
But there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
Yes, hence why you would have to check the CVSS of all of those.
And they just changed the CVE rules to include non-exploitable bugs too.
My theory is its to pump AI ‘discoveries’ numbers
Most of them are just crashing bugs. Worth fixing but you don’t need to panic. If anyone exploits them, then A) you’ll know about it, and B) they won’t get away with anything sensitive.
No need to panic? Tell that the kernel! :D
The kernel is really anxious though, panics all the time.
But crashing bugs are good for denial of service.