• Luci@lemmy.ca
    link
    fedilink
    English
    arrow-up
    11
    ·
    6 days ago

    Why so many, you may ask. Well, because of several reasons, one of them being the recent policy change in CVE assignment for the kernel project, where essentially any commit identified as fixing a potential security issue gets a CVE assigned, even if it’s a minor one or has no known exploit path.

    🙄

    • auzy1OPM
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      Also, a lot of tools like AI running more automated testing tbh. If it causes things to crash, that makes sense to assign a CVE

      However one thing that Linus has apparently complained about is that people are loading up modules in a weird way (with fake hardware), and sending bad data. Apparently the issue has caused so many bad reports that from my understanding, they plan to mark the kernel as “TAINTED” if people do this for testing.

      Just because it’s possible to cause the kernel to crash if bad data is sent back, doesn’t mean that device will EVER send data to replicate that

    • klankin@piefed.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 days ago

      Is that change nothing but AI money influencing the policy?

      Like AI is such a money hole, they’re reinventing goalposts on every metric they measure.

      Personally, Imma start calling everything I do a CVE, cause you never know technically that shit I just took could have worsened my mood, made me sloppy with my key security, and got hacked. I’ve actually identified 2 CVEs just this morning at this rate.