Arthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 4 days agoSeveral vulnerabilitieslemmy.mlimagemessage-square43fedilinkarrow-up1378arrow-down14
arrow-up1374arrow-down1imageSeveral vulnerabilitieslemmy.mlArthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 4 days agomessage-square43fedilink
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up105arrow-down1·4 days agoTo add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
minus-squareslazer2au@lemmy.worldlinkfedilinkEnglisharrow-up37arrow-down2·4 days agoBut there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up25arrow-down1·4 days agoYes, hence why you would have to check the CVSS of all of those.
minus-squareklankin@piefed.calinkfedilinkEnglisharrow-up14·4 days agoAnd they just changed the CVE rules to include non-exploitable bugs too. My theory is its to pump AI ‘discoveries’ numbers
To add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
But there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
Yes, hence why you would have to check the CVSS of all of those.
And they just changed the CVE rules to include non-exploitable bugs too.
My theory is its to pump AI ‘discoveries’ numbers