Release managers' mistake
Posted Dec 2, 2003 9:44 UTC (Tue) by
wichert (subscriber, #7115)
In reply to:
Release managers' mistake by bgilbert
Parent article:
A Debian kernel security update
Kernel release managers definitely care about security and kernel security are always discussed by vendors and the relevant kernel folks. In this case the fix had been known for a while, but nobody realised just how dangerous this bug was. With a project as complicated and filled with subtleties that is not all that unexpected.
Your example of Alan's fix for the ptrace bug actually is a fine counterexample of your suggestion that kernel maintainers do not care about security: it was quickly fixed even though the fix broke a few things. Alan fixed the ptrace hole quickly to fix the security problem and relied on others to fix the fallout while he could focus on more pressing issues.
(
Log in to post comments)