Live data from Hacker News

Over 400 Linux CVEs published in the last 24 hours alone

lore.kernel.org

11–20 of 52 posts

Re: Over 400 Linux CVEs published in the last 24 hours alone

#11
post #7
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it. We patched for a CVE last week that a malicious usb sound card device could be use the gain root. On a Vm? Is that something we really need to worry about??

It's asymmetric warfare. It costs them little to demand a false positive be acted upon, but costs you plenty to refute it.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#12

Might need to silently archive those Microsoft Patch Tuesday jokes...

Those that actually understood security, and weren't on some kind of open-source enforcement mission in life, always knew the "Linux doesn't get viruses" statements would not age well. https://blog.desdelinux.net/en/virus-in-gnulinux-reality-or-...

> Those that actually understood security....

Indeed, and those who actually understood software development always knew vulnerabilities can occur just as easily as bugs.

And in some cases more easily than bugs, because many of modern vulnerabilities are so subtle, especially where crypto is involved.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#15

Might need to silently archive those Microsoft Patch Tuesday jokes...

Those that actually understood security, and weren't on some kind of open-source enforcement mission in life, always knew the "Linux doesn't get viruses" statements would not age well. https://blog.desdelinux.net/en/virus-in-gnulinux-reality-or-...

You should be careful not to conflate viruses and CVEs.

Considering no Linux distro come with an antivirus by default, Linux as a desktop was always extremely vulnerable to bad actors.

As a server, I would argue otherwise.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#16
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

I only sampled them, but all the ones I sampled are announcements of fixes, not just vulnerabilities. This seems to be downstream of the "intake" already.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#17
post #7
post #4

I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could…

In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it. We patched for a CVE last week that a malicious usb sound card device could be use the gain root. On a Vm? Is that something we really need to worry about??

Its the same at most orgs. Very rare for a vuln remediation program to utilize a truly risk based approach. They would have to trawl through and understand thousands of vulns and the context of your org. There's probably a market for some tool to accomplish this if the larger players haven't attempted already.

Re: Over 400 Linux CVEs published in the last 24 hours alone

#19

I guess very few around here remember the minor fuzz about this from a few years ago? The Linux Kernel Project became their own CNA (CVE Numbering Authority). A CVE is now slapped onto practically every bug fix that is back ported to a stable kernel, resulting in a flood of CVEs. A blog post about this, published at the time: https://sigma-star.at/blog/2024/03/linux-kernel-cna/ The title is editorialized (i.e. the OP…

(Email the mods to clear up the editorial title problem; footer contact link.)
Post reply on HN