Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

301–310 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#301
post #300

Earlier quoted context omitted.

I strongly disagree. I want the information. I don't want to wait longer to find out about critical vulnerabilities so that researchers can fully genuflect to whatever Linux distribution norms people on message boards have. Their "actions" were to disclose a vulnerability that already existed and was putting people at risk. It's an absolute good. If it helps you out any, even though my logic was absolutely the same a…

I do get that, this era of automation is too responsive to not go public to provoke action. I think I might just be wistful of an era in which the alternate path might have made a difference. Sorry to pile on.

You're not piling on and I'm glad to have the opportunity to expand on my point.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#302

Earlier quoted context omitted.

I'm not advocating for delaying the disclosure at all; my point is, if you see your initial disclosure to the kernel didn't go anywhere, to be responsible is to put in a little extra effort to ensure the fix is picked up before you disclose.

"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking. Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicat…

The kernel devs patched it! They patched it weeks ago

FTFA:

> I see that on the 11th of April 6.19.12 & 6.18.22 were released with the fix backported.

> Longterm 6.12, 6.6, 6.1, 5.15, 5.10 have not received the fix and I don't see anything in the upstream stable queues yet as I write.

I wouldn't go so far as to call this "the kernel devs patched it". Virtually none of the kernels that distro's are actually using today have received a fix. This looks like an extremely lackluster response from the kernel security team.

Pretty much the only non-rolling distro's that are shipping a fixed kernel are Fedora 44 and Ubuntu 26.04, both released in the last few weeks. Their previous releases both shipped with Linux 6.17 which is still vulnerable today!

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#303
post #49

Earlier quoted context omitted.

Not true, if there’s any evidence of the exploit being used in the wild, it’s much more responsible to release immediately. Considering that the patches have been available for a while, someone surely reversed what they were for and was actually exploiting this in the wild. In the age of AI, I’d argue that “responsible disclosure” is dead. Arguably even in closed source projects. Just ask Claude to do a diff between…

But they didn't release immediately -- they waited a month, but forgot to tell the distros, and forgot to check if waiting a month had actually lead to distros picking up the patches and shipping them.

Which just reinforces my point. The patch was available, therefore, where the exploit lies was also available.

Linux kernel is one of the most audited open-source projects ever. I guarantee you that someone did reverse the patch.

> but forgot to tell the distros

Probably an oversight, but irrelevant. The bug was in the linux kernel. It's insane to suggest that they should have notified everyone shipping the linux kernel.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#304
post #298

Earlier quoted context omitted.

> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. Not "separately to every single downstream", there is the "linux-distros" mailing list for disclosures: https://oss-security.openwall.org/wiki/mailing-lists/distros This random blogpost from 2022 serves as a proof that disclosing kernel vulnerabilities to the distros list is a well-k…

Why is it the job of the kernel to notify the distros? Why isn't it the job of the distros to keep up on upstream security disclosures? Expecting a FOSS project to go track down all of its (millions of?) users seems like a very unreasonable expectation, and is well outside of their scope of responsibility. People have gotten so used to the Github flavour of free-labour, social-network-style FOSS that they've forgotte…

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#305
post #187

Earlier quoted context omitted.

Yes, it's just incompetence from everyone involved, not malice. The company making the disclosure doesn't actually care, and the kernel processes are ineffective.

No, it's incompetence from everyone involved except the company making the disclosure , which, despite the fact that the existing norms are not in fact binding (like people downthread seem to believe), they followed.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#307
post #71

Earlier quoted context omitted.

Especially since the reporter is explicitly asked not to notify the distro teams first. https://docs.kernel.org/process/security-bugs.html ```As such, the kernel security team strongly recommends that as a reporter of a potential security issue you DO NOT contact the “linux-distros” mailing list UNTIL a fix is accepted by the affected code’s maintainers and you have read the distros wiki page above and you fully unde…

I don't get why the initial reporter should have to do that legwork. The kernel maintainers should be doing that.

Ffs, we're talking about open source projects here. Those mailing lists, mentioned there, ARE PUBLIC.

Make them private? Now you have a nice stream of zero days, long before fixes are available, making bad actors who made it in filthy rich.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#308
post #298

Earlier quoted context omitted.

> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. Not "separately to every single downstream", there is the "linux-distros" mailing list for disclosures: https://oss-security.openwall.org/wiki/mailing-lists/distros This random blogpost from 2022 serves as a proof that disclosing kernel vulnerabilities to the distros list is a well-k…

Why is it the job of the kernel to notify the distros? Why isn't it the job of the distros to keep up on upstream security disclosures? Expecting a FOSS project to go track down all of its (millions of?) users seems like a very unreasonable expectation, and is well outside of their scope of responsibility. People have gotten so used to the Github flavour of free-labour, social-network-style FOSS that they've forgotte…

Where do you suggest they should have kept up on this disclosure?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#309

Earlier quoted context omitted.

> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. Not "separately to every single downstream", there is the "linux-distros" mailing list for disclosures: https://oss-security.openwall.org/wiki/mailing-lists/distros This random blogpost from 2022 serves as a proof that disclosing kernel vulnerabilities to the distros list is a well-k…

It is literally not the vulnerability researcher's problem to solve or address this.

Agree, but then where does the accountability lie? Presumably with the kernel maintainers themselves, correct? SOMEONE dropped the ball here. If we can't point the finger correctly, that seems like a problem in of itself.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#310
post #116

Earlier quoted context omitted.

So if I found a vulnerability that lets hackers withdraw withdraw all the money in your account without a trail on where the money went, you'd be fine with them disclosing it to the public at the same time as the bank learns about it? Even when there is no known use case of the attack (other than the security researcher's)? > The vulnerability exists for me either way, and I'd rather have the chance to know about it…

Yep, I'd be fine with that. My bank has insurance, and my money would be returned.

And what is the insurance in the Linux case, for which the analogy was being made?
Post reply on HN