• eldavi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Why so many, you may ask. Well, because of several reasons, one of them being the recent policy change in CVE assignment for the kernel project, where essentially any commit identified as fixing a potential security issue gets a CVE assigned, even if it’s a minor one or has no known exploit path.

    wtf?!!! why?!

    • ruby@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      0
      ·
      3 days ago

      i’m pretty sure the kernel itself does that to themselves too. basically there’s so much code in the kernel that if any bug, even if small, could possibly under a specific configuration result in some device out there having its security weakened, they prefer to be on the safe side and assign a cve.