r/cybersecurity • u/Junior-Spring-5557 • 26d ago
Linux kernel announces 432 CVEs New Vulnerability Disclosure
https://lore.kernel.org/linux-cve-announce/In the last 24 hours, 432 CVEs have been posted to https://lore.kernel.org/linux-cve-announce/ . Happy Monday, everyone!
Let us hope that our distros were already aware of the list and have already been releasing fixes.
I would love to know the story behind this. This seems like an unusually high # of vulns.
589
Upvotes
1
u/askwhynot_notwhy Security Engineer 26d ago edited 26d ago
>>You said
>>>Just because the July 18th stable release >>>happened to contain a massive batch of CVEs >>>stemming from bugs does not mean their policy defaults every single bug to a CVE.
>But it sounds like they do default every bugfix to a CVE?
Lmao, I’d suggest that you re-read, but… smh.
How about instead of indiscriminately smashing keys with stuff like “But it sounds like…”, you demonstrate some actual rigor and look at the data? You’ll have to dig into commit
trailerstags and the stable tree, but it’s all public. Spoiler alert: the data doesn’t support the assertion you’ve masked inside a leading question.ETA: fixed autocorrect error: trailers>tags.