oss-sec mailing list archives
Re: Details on this supposed Linux Kernel ksmbd RCE
From: Marcus Meissner <meissner () suse de>
Date: Fri, 23 Dec 2022 09:17:28 +0100
Hi folks, tldr: I requested 5 CVEs for the new ZDI issues Josh and Jan referenced. long form: Nice surprise 1 day before Christmas. On Fri, Dec 23, 2022 at 08:06:28AM +0100, Greg KH wrote:
On Thu, Dec 22, 2022 at 04:49:04PM -0500, Jan Schaumann wrote:Lastly, given that this is a coordinated disclosure, I don't know why there are no CVE IDs reserved for these.The kernel developers do not work with CVEs at all as they are not all that relevant for the most part for kernel issues.
We know.
MITRE agrees with us will not even give them to us if we ask for them :)
Not sure why they do not like you, but to be very clear anyone else can requests CVEs for the kernel, (except the blacklisted drivers/staging/ area).
Some Linux companies still insist on assigning CVEs, but that's primarily to help enable their internal engineering processes more than anything else.
The whole software industry operates with CVEs as primary identifiers at this time, so it is not just some "internal engineering processes".
As an alternative, please look at the GSD (Global Security Database, https://globalsecuritydatabase.org/) for which the kernel does get ids assigned for issues like this, and many many others.
Perhaps this or any of the other ID spaces / databases will be taking off in the near future, but the main industry index is CVEs at this time. That said, I have just filed 5 CVE requests for the 5 ZDI issues cross- referencing the Linux kernel mainline commits. FWIW, they were fixed in mainline in July and no one had spotted them, which of course underlines Gregs point and that there are not enough watchers. Ciao, Marcus
Current thread:
- Details on this supposed Linux Kernel ksmbd RCE Josh Bressers (Dec 22)
- Re: Details on this supposed Linux Kernel ksmbd RCE Jan Schaumann (Dec 22)
- Re: Details on this supposed Linux Kernel ksmbd RCE Greg KH (Dec 22)
- Re: Details on this supposed Linux Kernel ksmbd RCE Marcus Meissner (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Eric Biggers (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Jeffrey Walton (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Sasha Levin (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Greg KH (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Marcus Meissner (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE John Helmert III (Dec 23)
- Re: Details on this supposed Linux Kernel ksmbd RCE Marcus Meissner (Dec 27)
- Re: Details on this supposed Linux Kernel ksmbd RCE Greg KH (Dec 22)
- Re: Details on this supposed Linux Kernel ksmbd RCE Marcus Meissner (Dec 27)
- Re: Details on this supposed Linux Kernel ksmbd RCE Jan Schaumann (Dec 22)
- Re: Details on this supposed Linux Kernel ksmbd RCE John Helmert III (Dec 23)