Stupidity . . . or not
Stupidity . . . or not
Posted May 8, 2026 0:02 UTC (Fri) by himi (subscriber, #340)In reply to: Stupidity by jpeisach
Parent article: Dirty Frag: a zero-day universal Linux LPE
> Because the embargo has currently been broken, no patch or CVE exists. After consultation with the
> maintainers on linux-distros@vs.openwall.org and at their request, this Dirty Frag document is being
> published. For the disclosure timeline, refer to the technical details.
In other words, the publication of this information was done in consultation with, and at the request of, the kernel and distro security groups - not something that deserves to be called "stupidity". Particularly given there's a pretty simple mitigation (blacklisting and removing the vulnerable modules).
