Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

121–130 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#121

Earlier quoted context omitted.

“The choice that maximizes potential damage isn’t irresponsible, because it means I can mitigate my own systems immediately.” That’s what you’re saying here.

They're literally just restating the argument for full disclosure security. This is one of the oldest debates in information security.

The disclosure doesn't appear very "full". Looks like this was slipped into mainline linux among dozens of other mostly-irrelevant "CVEs" with nobody highlighting the fact that it is in fact dirty-cow-on-steroids.

https://x.com/spendergrsec/status/2049566830771970483

https://lore.kernel.org/linux-cve-announce/2026042214-CVE-20...

Or is everyone expected to upgrade and reboot every 48 hours for all eternity and just deal with potential regressions all the time?

I think this reflects poorly on the original reporters. If you have a weaponized 700-byte universal local root exploit script ready to go, perhaps you should coordinate with major distros for patches to be available before unleashing it on the world. No matter how "veteran" you are.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#123
post #45

Earlier quoted context omitted.

well now everyone does, so the irresponsible disclosure makes it significantly worse.

It’s your opinion that it’s irresponsible and that it makes something worse.

The public disclosure page has a big blue "Get the exploit" button.

It's an advertisement for an unpatched critical exploit and apparently some kind of infosec company.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#124
post #41

Earlier quoted context omitted.

Partly they already have enough on their plate. It's up to the reporter to pick how to handle the disclosure, and unless a specific maintainer chooses to handle it, the Linux security team clearly says they won't. Partly they have a strong belief that all kernel bugs are vulnerabilities and all vulnerabilities are just bugs; sometimes taken to the extreme in both ways (on one hand this case where the vulnerability is…

Seems a little crazy. Somebody should evaluate blast radius and do appropriate distro notifications in a case like this (I presume the impact was part of the disclosure, so not much extra work).

You know the linux kernel is a free software project right? If you think “somebody should” do a thing but you aren’t prepared to do it yourself then you should maybe ask for a full refund.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#125
post #116

Earlier quoted context omitted.

So if I found a vulnerability that lets hackers withdraw withdraw all the money in your account without a trail on where the money went, you'd be fine with them disclosing it to the public at the same time as the bank learns about it? Even when there is no known use case of the attack (other than the security researcher's)? > The vulnerability exists for me either way, and I'd rather have the chance to know about it…

Yep, I'd be fine with that. My bank has insurance, and my money would be returned.

You're missing the point (not sure if you're just being dense on purpose...). If you're bank would just return the money then its not a good analogy. If someone gains root access to your machine, presumably they can do damage that can't be undone. In other words, to continue the bank analogy, they would take all your money and you would have no way of getting it back. Presumably, you would not be ok with this. And even if, for some weird reason, you were ok with that, 99.9% of all other people would not be ok with it.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#126

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Counterpoint. End users have a right to mitigate this issue on their systems. It is a really really bad look for Linux, puts a bit of water on all hype around switching from Windows.

[flagged]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#127
post #39

Earlier quoted context omitted.

Who knows how many attackers had found this vulnerability and had already been using it prior to this research finding it?

Argument from uncertainty is not a good way to reason about this. I could equally ask: "Who knows how many attackers learned about this vulnerability from this disclosure, and used it before the distributions fixed it?"

Yes, you could. Thats the core of my point: there is no Right way to handle vulnerability disclosure. There are many competing factors, most of them have major elements of uncertainty because you can’t know who knows what or how various projects or stakeholders will react.

So maybe folks should take a break from the kind of armchair quarterbacking that this was “incredibly irresponsible”, as was done upthread, or that the researchers should be blacklisted for life, as a parallel commenter stated.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#128

Earlier quoted context omitted.

“Made it into the wild?” Patches landed a month ago. Should they also wait until my linksys router from 2018 has a patch ready?

It's a local vulnerability at least. How many people do you let log in to your router? With the way linux is used these days, I'd guess the number of systems with untrusted local users is pretty limited. Even with shared hosting, you generally have root in your VM or container anyway. Unless this enables an escape from that? Still the risk that people who run "curl | bash" without care could get bitten, but usually i…

> With the way linux is used these days, I'd guess the number of systems with untrusted local users is pretty limited

Things like HPC clusters are multiuser & don't entirely trust their users. If they did we wouldn't need users/groups/permissions etc in the first place.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#129
post #82

Earlier quoted context omitted.

> It was extremely irresponsible As a user and admin I disagree. Makes one appreciate what a masterful bit of lexical-engineering “Responsible” Disclosure is, kinda like “Secure” ( from me, not for me) Boot — “Responsible” Disclosure is 100% about reputation-management for the various corporation/foundation middleman entities sitting between me and my computer. Those groups don't care that my individual computer is v…

“The choice that maximizes potential damage isn’t irresponsible, because it means I can mitigate my own systems immediately.” That’s what you’re saying here.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#130
post #82

Earlier quoted context omitted.

> It was extremely irresponsible As a user and admin I disagree. Makes one appreciate what a masterful bit of lexical-engineering “Responsible” Disclosure is, kinda like “Secure” ( from me, not for me) Boot — “Responsible” Disclosure is 100% about reputation-management for the various corporation/foundation middleman entities sitting between me and my computer. Those groups don't care that my individual computer is v…

“The choice that maximizes potential damage isn’t irresponsible, because it means I can mitigate my own systems immediately.” That’s what you’re saying here.

What the heck is up with people today.

Using quotes around something where you’re actually doing a strawman paraphrase of another commenter you disagree with is bad form.

Post reply on HN