Live data from Hacker News

Over 400 Linux CVEs published in the last 24 hours alone

lore.kernel.org

21–30 of 52 posts

Re: Over 400 Linux CVEs published in the last 24 hours alone

#21
post #7
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it. We patched for a CVE last week that a malicious usb sound card device could be use the gain root. On a Vm? Is that something we really need to worry about??

[flagged]

Re: Over 400 Linux CVEs published in the last 24 hours alone

#23
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

The linux kernel team disagrees with your approach but what do they know?

> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#24
post #7

Earlier quoted context omitted.

In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it. We patched for a CVE last week that a malicious usb sound card device could be use the gain root. On a Vm? Is that something we really need to worry about??

[flagged]

Sometimes it is cheaper.

Most businesses run on a, "least to be in compliance" model.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#27
post #18

Amazing how people think this means anything

This sounds like cope. We are going to see more of this with LLMs being able to uncover hundreds of bugs in projects just like Linux.

This has nothing to do with LLMs.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#28
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

[deleted]

Re: Over 400 Linux CVEs published in the last 24 hours alone

#29

Might need to silently archive those Microsoft Patch Tuesday jokes...

If they were there this whole time but only discovered now, were they really a threat? The reflexive response to this is "those could be exploited for years and we'd never know", but if it was discovered, it obviously wasn't impacting you personally. If they were under lock and key at the NSA and only judiciously used for secret spy BS, that's effectively the same as not existing. Clearly they weren't discovered by all the white hats for this whole time.

Also, if Microsoft hypothetically open sourced their code, do you think there would be more, less, or the same number of CVEs? I would guess more.

I don't want to go too far to defend Linux. I want to make the case that it has been the more secure OS this whole time.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#30
post #7

Earlier quoted context omitted.

In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it. We patched for a CVE last week that a malicious usb sound card device could be use the gain root. On a Vm? Is that something we really need to worry about??

[flagged]

Setting aside the merits of DEI, this anecdote isn't indicative of it. I recall a client getting HP to do a security audit of a site I was working on, and it absolutely read like a committee put together a checklist of every possible thing they could think of. They flagged that user sessions weren't pinned to IP addresses, despite this being right around the time that cell phones became popular and their suggested remediation would have caused users who were riding on a bus between cell towers to get logged out while they were using the site.

There were plenty of even less useful flags, but that one stood out to me for some reason.

"Checklist security" has been a thing for ages.

Post reply on HN