Elektrine lite

← Feed

@gregkh@social.kernel.org

Post #1984268

2026-05-03 06:23 UTC

@joshbressers I will quote this in many presentations in the future because it is so true: "The Kernel assigns lots of CVEs. They say it’s because they don’t really know how the Kernel is being used, so they err on the side of caution. Companies hate this because they have to deal with a lot of CVEs. Does the Kernel do this because it’s easier or do they have some sort of secret nefarious reason? Probably because it’s just easier and they have zero downside to disclosing and moving on. " RE: https://infosec.exchange/@joshbressers/116507930206819253

Replies (3)

  • @buherator@infosec.place 2026-05-03 17:30

    @gregkh@social.kernel.org @joshbressers@infosec.exchange What you are describing is called a "negative externality".

    Open ##3138141

  • @gregkh@social.kernel.org @joshbressers@infosec.exchange Of course companies hate it. Plenty for bad reasons. But also for reasonable ones: Who can afford to reboot all machines every few days? 6.18 averaged a stable release every ~5.6 days, 6.12 averaged one every ~6.15 days. If you continually ask for unrealistic things ("All users of the xyz kernel series must upgrade." > once a week), folks *have* to stop listening after a while. What do you expect folks to actually do with prod systems?

    Open ##3189076

  • @gregkh@social.kernel.org @joshbressers@infosec.exchange It's kind of a shame how fast CVEs have become meaningless. There's so much compliance overhead associated with them that goes nowhere.

    Open ##3189078