MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
kernel
Search

The kernel becomes its own CNA

Tuesday February 13, 2024. 08:13 PM , from LWN.net
Greg Kroah-Hartman has announced
that the kernel project has been accepted as a CVE numbering authority
(CNA). The way that CVE numbers will be handled by the kernel is described
in this
documentation patch:

As part of the normal stable release process, kernel changes that
are potentially security issues are identified by the developers
responsible for CVE number assignments and have CVE numbers
automatically assigned to them. These assignments are published on
the linux-cve mailing list as announcements on a frequent basis.

Note, due to the layer at which the Linux kernel is in a system,
almost any bug might be exploitable to compromise the security of
the kernel, but the possibility of exploitation is often not
evident when the bug is fixed. Because of this, the CVE assignment
team are overly cautious and assign CVE numbers to any bugfix that
they identify. This explains the seemingly large number of CVEs
that are issued by the Linux kernel team.
https://lwn.net/Articles/961961/

Related News

News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Sat 27 - 14:54 CEST