Hacker News new | ask | show | jobs
by philipwhiuk 862 days ago
Every bugfix in the kernel is now a CVE. That's awful.

Every unfixed security issue is now no longer assigned a CVE until it's fixed. That's even worse.

2 comments

This will be interesting, if another linux vendor assigns a CVE and upstream duplicates the older CVE usually takes presedence, and they need to mark it as a duplicate, more houskeeping than just assigning it when they know about it.

I'm glad the LK finally has come to this conclusion, I dont care if it ends up exploding and using a lot of CVE's..

Good Work.

time for security researchers to drop CVEs and a start new scheme?

how about: CVF

Cv6 - 128 bits and never adopted.
Never is a bit harsh. Just a few decades...and a few more.