Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

361–370 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#361
post #321
post #298

Earlier quoted context omitted.

Why is it the job of the kernel to notify the distros? Why isn't it the job of the distros to keep up on upstream security disclosures? Expecting a FOSS project to go track down all of its (millions of?) users seems like a very unreasonable expectation, and is well outside of their scope of responsibility. People have gotten so used to the Github flavour of free-labour, social-network-style FOSS that they've forgotte…

> Why isn't it the job of the distros to keep up on upstream security disclosures? They can't, because (responsible) security disclosures are private, _not public_. That's the whole point of the system: notify the developers in private ahead of time (usually 30, 60 or 90 days) so they can write, test and roll-out the fixes before you release the info to the whole world. This is to minimize the time between when bad a…

It would be best if distros kept tap on kernel changes and update as soon as possible when they see a security issue fixed.

Sending emails to some big distros would still result with e.g. Gentoo not getting that info because they are not a big distro.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#362
The most interesting exchange, related to disclosure, is this one:

https://www.openwall.com/lists/oss-security/2026/05/01/3

> Nope, sorry, we are NOT allowed to notify anyone about anything "ahead of time" otherwise we will have to tell everyone about everything. That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it.

greg k-h

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#363
post #257

Earlier quoted context omitted.

I'd also prefer immediate disclosure, but I don't get how waiting a month without telling anyone is good regardless of which side you land on.

> I'd also prefer immediate disclosure wait, what? you are in another comment thread, of this very post, calling these reporters bumbling and incompetent for their disclosure. "merely bumblingly incompetent and overly eager to get their marketing pitch out the door " - that is your quote. you also said "Basic care would involve making sure the patches had made it into the wild before ending the embargo ", which is th…

Yes, if you release the vulnerability as soon as possible, that's a good choice. If you have an embargo and make sure that fixes get out to users in a timely manner before ending the embargo, that's also a reasonable choice.

If you're going wait a month between landing the patch (possibly notifying attackers), but not notify the people who may get the patch to users, it seems like something was mishandled.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#364

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

i have no problem with disclosing a vulnerability 30 days after its patched in the thing you reported to. (in fact, for those unaware, this is the same policy that google's project zero uses: "90+30" https://projectzero.google/vulnerability-disclosure-policy.h... ) the real problem is: > It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. the report…

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#365

Earlier quoted context omitted.

The fact that you had to take a whole paragraph to explain the contortionist arrival at something that isn't even really super clear after you explained it (you kinda pointed the finger both at end users and at distro maintainers simultaneously) and essentially boils down to "well, you as the end user need to be following kernel CVE's and can't trust distro maintainers to do it" does in fact indicate that there is a…

The real advantage of Microsoft is that there is someone you can sue! Linux like every open source project is just a bunch of people who are YOLOing it. Not something you use for your fortune 500 critical mission infrastructure.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#366
post #240

Earlier quoted context omitted.

I'm confused. Can you explain how this applies to the current situation, where no vuln reports were submitted to the groups responsible for distributing patches?

> the groups responsible for distributing patches? Those groups don't exist, to my knowledge. And probably can't, realistically speaking.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#367

Earlier quoted context omitted.

The fact that you had to take a whole paragraph to explain the contortionist arrival at something that isn't even really super clear after you explained it (you kinda pointed the finger both at end users and at distro maintainers simultaneously) and essentially boils down to "well, you as the end user need to be following kernel CVE's and can't trust distro maintainers to do it" does in fact indicate that there is a…

The real advantage of Microsoft is that there is someone you can sue! Linux like every open source project is just a bunch of people who are YOLOing it. Not something you use for your fortune 500 critical mission infrastructure.

I thought this is why red has exists?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#369

Earlier quoted context omitted.

To be clear, the vulnerability existed in Linux, not in Xint Code. It existed whether this group disclosed it or not. Knowledge of it and exploits may have already been bought and sold among various groups with various motives including crime, terrorism, or cyberwarfare who likely made good money off it if this happened. In that world, the vulnerability has more value to those who seek to exploit it for their own mot…

Yes, and that's why we have the responsible disclosure protocol. It wasn't correctly followed here.

Which part was not correctly followed?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#370

Earlier quoted context omitted.

> where no vuln reports were submitted to the groups responsible for distributing patches? the vulnerability report was submitted to the kernel security team and appropriate kernel maintainers. those are the people responsible for patching the kernel, which they did 30 days ago.

> those are the people responsible for patching the kernel, which they did 30 days ago. They patched 2 of 7 supported kernels.

Guess the other supported kernels aren't supported enough
Post reply on HN