Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The systemd developers "forget" to file a lot of the CVE bugs that should have been filed, so the CVE is incomplete in regards to the serious security issues that have affected systemd.


I still remember that time when systemd developers argued that a privilege-escalation bug systemd enabled was not really a bug. The criteria those developers* use to determine what merits a CVE filing doesn't quite match up with what you'd expect, so CVE count isn't a good metric for systemd security.

* Unfortunately, they aren't alone in their sloppy handling of security issues. Rust is also another project that is known to not file CVEs for serious bugs if they occur in previous releases.


So does the linux kernel as current, previous or even release candidates..


You can document this, right? The researcher who finds a problem should be able to request a CVE even if the upstream doesn't acknowledge it.


The theory is good. :)

Weirdly though, getting a CVE assigned can be a real PITA (and unsuccessful). The people who do the CVE assignment are generally overloaded, so lower impact/priority stuff often seems to get missed or not bothered with.


This hasn't been the case for a number of years, Mitre has seriously picked up their game, and you can talk to linux vendors such as Red Hat, Ubuntu and SuSE who also have blocks of CVE's assigned for things they shipped.

The alternative is DWF, which would be more popular if this was a more common problem.


> This hasn't been the case for a number of years ...

Thanks, that's really good news.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: