Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

511–520 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#511

Earlier quoted context omitted.

> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. It's 2026. We're more than 30 years into the Linux ecosystem. I don't believe this bullshit for a moment. Given how trivially users can implement mitigation, distributions could have done _something_ to protect their users prior to publication date. A handful of messages is all that…

> distributions could have done _something_ to protect their users prior to publication date. yeah, distributions could be following the kernel updates more closely and they would have been patched prior to publication. mainline was patched 30 days before publication. it is not the reporter's responsibility to babysit the linux distributions.

And here, with this comment, we see how the overall system functions: nobody actually cares what is going on with anything outside of themselves. It is a large group of individualized nihilists with total disregard to everyone, and you will provide lengthy justifications to maintain this system, as is.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#512

Earlier quoted context omitted.

Why would he ever... not release a new version? I don't get what you're trying to say - I'm stating Greg's explicit policy on the topic. If he did something outside of that policy, that wouldn't change anything.

If he doesn't believe in the "concept of vulnerabilities" then it is remarkable that he released a 6.12 targeted on this one fix. Why would he do that otherwise?

Sorry but he literally doesn't and nothing you say is going to change that he has explicitly stated that. This isn't up for debate, go ask him yourself, literally go to the first blog post on his site.

As for the latest patch, Greg is currently being forced to clean up a big fucking mess by external parties. And he's miserable about it.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#513
post #505

Earlier quoted context omitted.

Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…

> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…

You are strongly implying that keeping the vulnerability secret is following of what you quoted. But that’s the rub. Many of us think the opposite. Not disclosing this would have been the violation.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#514
post #505

Earlier quoted context omitted.

Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…

> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…

It’s a commonly followed practice for some people. Notably it’s what was done here: they coordinated disclosure with the Linux kernel devs. And now folks are angry that they didn’t also coordinate with yet more downstream projects.

> For reference, the standard is 30 for the developer to fix and 90 for it to land on machines.

I’ve never seen that as a standard anywhere.

Are you thinking of this? https://projectzero.google/vulnerability-disclosure-policy.h...

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#515
post #326

Earlier quoted context omitted.

But now millions more people know about how to exploit it who didn't before. I don't see why you're struggling with this.

You can't bully me into agreeing with you. Why are you struggling with that?

That was my first comment in the thread. I'm not bullying you; if you don't want people to challenge your statements then you came to the wrong place ;-)

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#516
post #505

Earlier quoted context omitted.

Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…

> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…

You're trying to extrapolate on this specific scenario from Wikipedia pages. Have you done any of this work? What have you done when you've reported a vulnerability to an upstream with dozens of downstreams? When your teammates have? You keep talking about "protocols" and "commonly followed practice" and "codes of ethics". Tell us more about the codes, protocols, and practices in your shop.

Nobody, for what it's worth, is arguing that major distros shouldn't have gotten some kind of notice. The problem is that the entity responsible for doing that isn't the vulnerability research lab. In fact, as a general procedural point, researchers can't go contact downstreams. They might be able to do so in the specific case of Linux, but you've tried to spin that possibility into a binding obligation derived from established practices, which: no. That's not a real thing.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#517

Earlier quoted context omitted.

It is literally not the vulnerability researcher's problem to solve or address this.

Brother, it is a simple email to a mailing list. They are professional security researchers, they must know this is the way it is done in the ecosystem. Kicking the can around leads nowhere.

Of course you want them to have sent an email to a mailing list. You're on a message board, and weren't involved in their disclosure process. Why not ask for everything that sounds reasonable to you? There's no cost to it for you. Maybe you can set their OKRs while you're at it.

There are (some, loose) norms of vulnerability disclosure, and this isn't one of them.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#518

Earlier quoted context omitted.

You're freaking out about the exploit being written in Python and occupying only a small number of bytes. Are you the LLM that wrote Xint's terrible landing page? If so, I have questions.

Oh come on, you know what I'm saying. It's small when written in python, which means any skid can spew it into a server he's got a shell on and get root in 2 seconds. He doesn't need to hope there's already a compiler installed, nor does he need to download some big tool. Just: cat | python3 && su , Ctrl-D And I'm sure it can be refined into something much more likable to the spooky types, if they haven't already don…

This is such a 1996 argument. It really was a big deal back then whether you had compilers on your multiuser SunOS boxes, because attackers would then use them to compile exploit.c.

The whole thread, really bringing me back to comp.security.unix. I'm not complaining! I miss comp.security.unix.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#519
post #179

Earlier quoted context omitted.

Let me make you aware of zerodium. A broker anyone can sell vulns to, that sells to unspecified buyers you do not need to know about.

FWIW, zerodium shut down in 2025. Or at least went dark ..

Just went dark.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#520
post #487

Earlier quoted context omitted.

None of this impacts disclosure norms. One important reason the clock starts ticking faster once any patch lands is that for serious attackers, the patch discloses the vulnerability. That's quadruply so in 2026, when many orgs are automatically pumping Linux patches through LLM pipelines to qualify them for exploitability. But it's been at least 15 years since "reversing means patches are effectively disclosures legi…

I'm not sure where in my post I challenged existing disclosure norms?

I don't know if you are or you aren't, but that's the overall topic of the thread, and I'm just clarifying that the details you're adding don't change any of the norms of disclosure.
Post reply on HN