oss-sec mailing list archives
Re: Linux kernel CVEs not mentioned on oss-security
From: Greg KH <greg () kroah com>
Date: Tue, 26 Sep 2017 17:04:46 +0200
On Tue, Sep 26, 2017 at 04:50:10PM +0200, Agostino Sarubbo wrote:
On martedì 26 settembre 2017 09:32:14 CEST Greg KH wrote:I guess this would be benefit for all.Define "all"You know, for example in Gentoo we are following the upstream releases. So from time to time we stabilize a newer kernel that "syncs" with upstream. This does not happen for non-rolling (release) distros that may want to patch/ backport the security fix.
I understand the issue well, I talk to companies all the time about this :) The rule for the kernel is, "if a distro/company/user is not following the stable kernel updates, they are on their own". I recommend either using the stable kernels, or paying for a company that knows what they are doing in this area and provides support (Red Hat, SuSE, etc.) And if you try to argue "just tell us what needs to be fixed", well, we are, am, we are providing about 10-12 patches a day that people should be incorporating into their kernels. Why they ignore that curated and tested stream of fixes is beyond me... Anyway, this is getting a bit off-topic here, sorry for the noise. Best of luck, greg k-h
Current thread:
- Linux kernel CVEs not mentioned on oss-security Priedhorsky, Reid (Sep 25)
- Re: Linux kernel CVEs not mentioned on oss-security Kurt Seifried (Sep 25)
- Re: Linux kernel CVEs not mentioned on oss-security Priedhorsky, Reid (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Simon McVittie (Sep 25)
- Re: Linux kernel CVEs not mentioned on oss-security Moritz Muehlenhoff (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Agostino Sarubbo (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Nicholas Luedtke (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Agostino Sarubbo (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Muhammed Mustapha Abiola (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Solar Designer (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Solar Designer (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Salvatore Bonaccorso (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Brad Spengler (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Kurt Seifried (Sep 25)
- Re: Linux kernel CVEs not mentioned on oss-security Kurt Seifried (Sep 26)