LWN.net Logo

The embedded long-term support initiative

The embedded long-term support initiative

Posted Oct 31, 2011 7:37 UTC (Mon) by Lionel_Debroux (subscriber, #30014)
In reply to: The embedded long-term support initiative by vonbrand
Parent article: The embedded long-term support initiative

Perhaps the number of vulnerabilities (multiple forms of DoS, information leaks, etc.), of various severity, which affect the kernel (as a special case of a huge piece of complex software), and are introduced and fixed by dozens every major kernel release ?
Counting CVEs is a weak measurement for the number of vulnerabilities, since only a small subset of vulnerabilities gets a CVE number.

A way to get a more secure Linux kernel is to use the large PaX/grsecurity patch, which prevents a number of classes of vulnerabilities from successful exploitation.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds