|
|
|
|
|
by svarog-run
1887 days ago
|
|
I feel like q lot of people here did not interpret this correctly. As far as it's known, garbage code was not introduced into kernel.It was caught in the review process literally on the same day. However, there has been merged code from the same people, which is not necessarily vulnerable. As a precaution the older commits are also being reverted, as these people have been identified as bad actors |
|
That means that the researchers got bogus code into the kernel, got it accepted, and then said nothing for two weeks as the bogus commit spread through the Linux development process and ended up in the stable tree, and, potentially, in forks.