Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

41–50 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#41
post #4

Earlier quoted context omitted.

Expecting people to do the right thing is a fundamental issue here. Why would you ever expect for all of vulnerabilities to be disclosed privately? There's very little actual incentive to do this. I'm honestly unaware of what systems could be put in place to prevent this but expecting people to always do the right thing is fantasy level thinking. I mean I bet the disclosers thought they were doing the right thing, he…

Why wouldn't the linux security team notify the main linux distributions?

Partly they already have enough on their plate. It's up to the reporter to pick how to handle the disclosure, and unless a specific maintainer chooses to handle it, the Linux security team clearly says they won't.

Partly they have a strong belief that all kernel bugs are vulnerabilities and all vulnerabilities are just bugs; sometimes taken to the extreme in both ways (on one hand this case where the vulnerability is almost ignored; on the other hand, I saw cases where a VM panic that could be triggered only by a misbehaving host—which could just choose to stop executing the VM—was given a CVE).

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#42
post #4

Earlier quoted context omitted.

Expecting people to do the right thing is a fundamental issue here. Why would you ever expect for all of vulnerabilities to be disclosed privately? There's very little actual incentive to do this. I'm honestly unaware of what systems could be put in place to prevent this but expecting people to always do the right thing is fantasy level thinking. I mean I bet the disclosers thought they were doing the right thing, he…

I can accept (and welcome) disclosure before there are patches. But publishing a working exploit together with the disclosure before patches are available is really really irresponsible, maybe even criminal. And no, the proposed mitigations don't help with half of the distributions out there...

> maybe even criminal

What’s your theory here? What crime?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#43

Earlier quoted context omitted.

I can accept (and welcome) disclosure before there are patches. But publishing a working exploit together with the disclosure before patches are available is really really irresponsible, maybe even criminal. And no, the proposed mitigations don't help with half of the distributions out there...

Patches were available for nearly a month.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#44
post #39

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Who knows how many attackers had found this vulnerability and had already been using it prior to this research finding it?

well now everyone does, so the irresponsible disclosure makes it significantly worse.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#45
post #39

Earlier quoted context omitted.

Who knows how many attackers had found this vulnerability and had already been using it prior to this research finding it?

well now everyone does, so the irresponsible disclosure makes it significantly worse.

It’s your opinion that it’s irresponsible and that it makes something worse.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#46

Earlier quoted context omitted.

The tenets of decency don’t need to be written down.

If you can't write it down, why would you expect it to be universal and enforceable? Different cultures exist and have different opinions on what "decency' means, after all. A security researcher's ethical obligations are to protect users over vendors (barring any contractual agreement in place). From what has been discussed in this thread, they meet that bar. Sure, they could have gone the extra mile to ensure the d…

> If you can't write it down, why would you expect it to be universal and enforceable?

and this is the problem. It used to be the case that if you were smart enough to find an exploit you were also smart enough to realise what would happen if you irresponsibly disclosed it. I guess these tools have made that pattern no longer apply.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#47

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Counterpoint. End users have a right to mitigate this issue on their systems.

It is a really really bad look for Linux, puts a bit of water on all hype around switching from Windows.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#48

Earlier quoted context omitted.

I can accept (and welcome) disclosure before there are patches. But publishing a working exploit together with the disclosure before patches are available is really really irresponsible, maybe even criminal. And no, the proposed mitigations don't help with half of the distributions out there...

Patches were available for nearly a month.

only for versions 6.19.12 & 6.18.22. older versions (which are used in distributions) are not ready yet.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#49
post #17

Earlier quoted context omitted.

Basic care would involve making sure the patches had made it into the wild before ending the embargo, and nagging the relevant parties if not. Edit: As of this writing, most distros including Redhat, Fedora, Debian Stable, do not have patches available in the package repos, though they're being actively worked on.

Not true, if there’s any evidence of the exploit being used in the wild, it’s much more responsible to release immediately. Considering that the patches have been available for a while, someone surely reversed what they were for and was actually exploiting this in the wild. In the age of AI, I’d argue that “responsible disclosure” is dead. Arguably even in closed source projects. Just ask Claude to do a diff between…

But they didn't release immediately -- they waited a month, but forgot to tell the distros, and forgot to check if waiting a month had actually lead to distros picking up the patches and shipping them.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#50

Earlier quoted context omitted.

The tenets of decency don’t need to be written down.

If you can't write it down, why would you expect it to be universal and enforceable? Different cultures exist and have different opinions on what "decency' means, after all. A security researcher's ethical obligations are to protect users over vendors (barring any contractual agreement in place). From what has been discussed in this thread, they meet that bar. Sure, they could have gone the extra mile to ensure the d…

different cultures have different views on disclosing vulnerabilities to distros before the public?
Post reply on HN