oss-sec mailing list archives

Re: Linux kernel CVEs not mentioned on oss-security


From: Agostino Sarubbo <ago () gentoo org>
Date: Tue, 26 Sep 2017 21:07:37 +0200

On martedì 26 settembre 2017 20:18:38 CEST Kurt Seifried wrote:
You can check the CVE Database? There is the official MITRE one:
cve.mitre.org and the DWF for Open Source (and yes, I lag in submissions to
MITRE) at https://github.com/distributedweaknessfiling/DWF-CVE-Database/ in
both cases the CVEs will have reference link(s) that ideally point to the
upstream making it easy to match up.

As pointed out in the past (maybe spender?) the real issue is when there is a 
silent fix of a vulnerability where the commit message does not clearly state 
about the security implication. Afaik it happens frequently.

-- 
Agostino Sarubbo
Gentoo Linux Developer


Current thread: