• eldavi@lemmy.ml
      link
      fedilink
      English
      arrow-up
      19
      ·
      1 day ago

      Why so many, you may ask. Well, because of several reasons, one of them being the recent policy change in CVE assignment for the kernel project, where essentially any commit identified as fixing a potential security issue gets a CVE assigned, even if it’s a minor one or has no known exploit path.

      wtf?!!! why?!

      • TrollAccount69@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        8 hours ago

        It’s because over the last decade the understanding and tools to take advantage of a bunch of small seemingly insignificant exploits in order to gain privileged access have become widespread.

        It’s the flip side of not trusting things written in rust to be effectively more secure just because it prevents someone from sticking their thumb between their fore and middle fingers and declaring they “got your stack”.

      • QuantumGirl@sh.itjust.works
        link
        fedilink
        arrow-up
        9
        arrow-down
        1
        ·
        23 hours ago

        i mean it makes sense to me, a vulnerability is a vulnerability regardless of whether it has been exploited or not

      • ruby@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        6
        ·
        22 hours ago

        i’m pretty sure the kernel itself does that to themselves too. basically there’s so much code in the kernel that if any bug, even if small, could possibly under a specific configuration result in some device out there having its security weakened, they prefer to be on the safe side and assign a cve.