LWN.net Logo

Release managers' mistake

Release managers' mistake

Posted Dec 2, 2003 9:44 UTC (Tue) by wichert (subscriber, #7115)
In reply to: Release managers' mistake by bgilbert
Parent article: A Debian kernel security update

Kernel release managers definitely care about security and kernel security are always discussed by vendors and the relevant kernel folks. In this case the fix had been known for a while, but nobody realised just how dangerous this bug was. With a project as complicated and filled with subtleties that is not all that unexpected.

Your example of Alan's fix for the ptrace bug actually is a fine counterexample of your suggestion that kernel maintainers do not care about security: it was quickly fixed even though the fix broke a few things. Alan fixed the ptrace hole quickly to fix the security problem and relied on others to fix the fallout while he could focus on more pressing issues.


(Log in to post comments)

Release managers' mistake

Posted Dec 2, 2003 12:41 UTC (Tue) by hppnq (subscriber, #14462) [Link]

Plus, IIRC Alan was very much involved with 2.2, which sort of makes the whole statement moot. ;-)

And of course it is the responsibility of sysadmins to apply patches or fix problems if necessary. Waiting for the next release is just not good enough, sometimes.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds