Get the latest tech news

The Linux kernel giving CVEs to all bugfixes is sort of predictable


One of the controversial recent developments in the (Linux kernel) security world is that the Linux kernel developers have somewhat recently switched to a policy of issuing CVEs for basically all bugfixes made to stable kernels. This causes the kernel people to issue a lot of CVEs and means that every new stable kernel patch release officially fixes a bunch of them, and both of these are making some people annoyed.

This development doesn't really surprise me (although I wouldn't have predicted it in advance), because I feel it's a natural result of the overall situation. For a long time, these third parties have wanted the main kernel to label all security fixes. And if things become annoying enough (what will all of the yelling), then the kernel developers may take steps to make the whole issue go away.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Linux

Linux

Photo of linux kernel

linux kernel

Photo of CVEs

CVEs

Related news:

News photo

Linux 6.9 arrives, plus Torvalds indicates Arm64 will get a bit more love

News photo

Rust 1.78 Upgrade For Linux 6.10, Dropping In-Tree "alloc" Fork To Save ~10k Lines

News photo

More ARM-Based Handheld Game Consoles Supported By Linux 6.10