Hacker News new | ask | show | jobs
by hkothari 3206 days ago
Am I missing something? The first line says: "Armis Labs revealed a new attack vector endangering major mobile, desktop, and IoT operating systems, including Android, iOS, Windows, and Linux, and the devices using them."

Why is the title singling out Linux? Reading through the rest of it, it seems like this is on pretty much everything.

2 comments

Windows was patched in July. Google has provided a patch for Android. Therefore, Linux is the only one left to make an announcement.
> Windows was patched in July. Google has provided a patch for Android. Therefore, Linux is the only one left to make an announcement.

For some reason, this vuln was not promptly disclosed to the Kernel security team. From the article:

  Google – Contacted on April 19, 2017
  Microsoft – Contacted on April 19, 2017
  Apple – Contacted on August 9, 2017
  Linux – Contacted August 15 and 17, 2017
Oh, and the most amusing one:

    Samsung – Contact on three separate occasions in April, May, and June. No response was received back from any outreach.
My 'flagship' OnePlus 5 is vulnerable today, according to their linked app.

While I totally believe that my device will receive a patch at some point in time, the majority of devices out there will probably never receive the patch Google provided. And even this recent phone is now vulnerable to a vulnerability that was just disclosed to the public at large..

I'd say Android is pretty much in deep (or rather: deeper than usual) shit as well, not just Linux

Microsoft is issuing security patches to all supported Windows versions at 10 AM, Tuesday, September 12.
We've updated the title from “Blueborne – Stack buffer overflow in Linux kernel Bluetooth”.