LWN.net Logo

Kernel.org's road to recovery

Kernel.org's road to recovery

Posted Oct 7, 2011 15:30 UTC (Fri) by vonbrand (subscriber, #4458)
In reply to: Kernel.org's road to recovery by mpr22
Parent article: Kernel.org's road to recovery

Count me in the camp with "any kernel bug that can't be shown to be absolutely neutral with respect to results is a security bug."


(Log in to post comments)

Kernel.org's road to recovery

Posted Oct 10, 2011 0:16 UTC (Mon) by malor (subscriber, #2973) [Link]

If all bugs are security flaws, then the security system in Linux is worthless.

Kernel.org's road to recovery

Posted Oct 10, 2011 1:41 UTC (Mon) by raven667 (subscriber, #5198) [Link]

While I think this is technically correct that the majority bugs have a security impact, that is not necessarily obvious when the bug is discovered, but that the conclusion is not useful for any practical decision making purpose. Whether you have a thousand security-critical bugs or a hundred doesn't matter because the attacker only needs one. Every system has them with greater or lesser levels of investigation as to whether the bugs are security relevant and disclosure of same. I believe, but cannot prove, that it is impossible to build a modern OS kernel with all the services it is expected to provide and not have security critical bugs. I don't think it is cause for giving up, even though as you said, the presence of bugs often allows security systems to be bypassed.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds