A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 15, 2024 6:22 UTC (Thu) by kees (subscriber, #27264)In reply to: A turning point for CVE numbers by bluca
Parent article: A turning point for CVE numbers
There are currently no plans to assign CVSS scores from cve@kernel.org, so this may happen externally, which kind of puts things back to square one: external entities will call out specific fixes as "important", and the cherry-picking will continue.
Honestly, when I would do security flaw lifetime analysis, I only ever looked at "Critical" and "High" CVEs (as rated by the Ubuntu security and kernel teams), since there was already such a giant long tail of "Medium" and "Low". E.g. see slides 4 & 5:
https://outflux.net/slides/2021/lss/kspp.pdf
