Trivial fixes might not be trivial
Trivial fixes might not be trivial
Posted Jun 28, 2019 3:01 UTC (Fri) by dps (guest, #5725)In reply to: CVE-less vulnerabilities by rweikusat2
Parent article: CVE-less vulnerabilities
In a former life I maintained a something based on a way out of security support version of RHEL. Even the most trivia kernell fix required dev testing on all supported hardware, which was several days work.
QA also had to do some more testing, so kernel upgrades where not something done lightly. A CVE and sufficient CVSS was required to overcome the resistance to changing anything.
I might have declared anything which broke on current arable versions to be bugware which te to be fixed, but was not in a position to do that.
