A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 15, 2024 0:50 UTC (Thu) by bluca (subscriber, #118303)In reply to: A turning point for CVE numbers by mfuzzey
Parent article: A turning point for CVE numbers
Of course it can and does, this is just the usual kernel developers misplaced exceptionalism and sense of grandeur. It's just some piece of software like many others.
> Even assuming the CVE does refer to a real vulnerability the impact is very usecase dependent.
And that's what the impact assessment and other data are used for, you are stating the obvious. "Does this exploit apply to our product" is the standard minimum assessment that everyone does.
> Also in my experience updates in the same stable kernel series very rarely cause issues
They break apart all the time, as soon as they involve anything that is not exercised on a couple dozens kernel developers laptops or desktops, and sometimes even there, like the disk corruption bug of a couple of months ago. New major releases are even worse, with userspace interfaces being intentionally broken left and right.
> At this point is there are few viable alternatives to Linux for vast swathes of applications.
I'm sure the developers of all past software that was once widespread and then faded into obscurity thought the same at some point or another. It just needs to stop making economic sense to use it, and that's exactly what it will happen - back to being a toy for hobbyists. We live in a capitalist society, and all those companies that are directly or indirectly sponsoring the vast, vast majority of development feel no attachment nor loyalty to anything but their share prices and profit margins.
