Arthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 1 day agoSeveral vulnerabilitieslemmy.mlimagemessage-square40linkfedilinkarrow-up11arrow-down10
arrow-up11arrow-down1imageSeveral vulnerabilitieslemmy.mlArthur Besse@lemmy.ml to linuxmemes@lemmy.worldEnglish · 1 day agomessage-square40linkfedilink
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up0·1 day agoTo add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
minus-squareklankin@piefed.calinkfedilinkEnglisharrow-up0·1 day agoAnd they just changed the CVE rules to include non-exploitable bugs too. My theory is its to pump AI ‘discoveries’ numbers
minus-squareslazer2au@lemmy.worldlinkfedilinkEnglisharrow-up0·1 day agoBut there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
minus-squaretruthfultemporarily@feddit.orglinkfedilinkarrow-up0·1 day agoYes, hence why you would have to check the CVSS of all of those.
To add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.
And they just changed the CVE rules to include non-exploitable bugs too.
My theory is its to pump AI ‘discoveries’ numbers
But there is a difference between an unauthenticated bug and a bug requiring an authenticated user getting some deserialised data.
Yes, hence why you would have to check the CVSS of all of those.