Hacker News new | ask | show | jobs
by verbatim 3357 days ago
I'm not sure how the Linux kernel handles these, but in some projects, this is intentional, the goal being to land the fix and make everyone safe before knowledge of how to exploit the bug is widely known.

Of course, sometimes just fixing up code for stability reasons may close a security hole that isn't really known or understood yet.

Not sure which was happening here.

2 comments

See http://yarchive.net/comp/linux/security_bugs.html

Relevant Linus quote: "I personally consider security bugs to be just "normal bugs""

I just mean the code delta itself; one line of code can make a lot of difference :)
Sometimes even one character can make a lot of difference: https://en.wikipedia.org/wiki/Mariner_1#.22The_most_expensiv...