oss-sec mailing list archives
Re: Linux kernel CVEs not mentioned on oss-security
From: Agostino Sarubbo <ago () gentoo org>
Date: Tue, 26 Sep 2017 21:07:37 +0200
On martedì 26 settembre 2017 20:18:38 CEST Kurt Seifried wrote:
You can check the CVE Database? There is the official MITRE one: cve.mitre.org and the DWF for Open Source (and yes, I lag in submissions to MITRE) at https://github.com/distributedweaknessfiling/DWF-CVE-Database/ in both cases the CVEs will have reference link(s) that ideally point to the upstream making it easy to match up.
As pointed out in the past (maybe spender?) the real issue is when there is a silent fix of a vulnerability where the commit message does not clearly state about the security implication. Afaik it happens frequently. -- Agostino Sarubbo Gentoo Linux Developer
Current thread:
- Re: Linux kernel CVEs not mentioned on oss-security, (continued)
- Re: Linux kernel CVEs not mentioned on oss-security Muhammed Mustapha Abiola (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Solar Designer (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Solar Designer (Sep 27)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Salvatore Bonaccorso (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Greg KH (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Brad Spengler (Sep 28)
- Re: Linux kernel CVEs not mentioned on oss-security Kurt Seifried (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Agostino Sarubbo (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Kurt Seifried (Sep 26)
- Re: Linux kernel CVEs not mentioned on oss-security Marcus Meissner (Sep 27)