A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 16, 2024 13:17 UTC (Fri) by hkario (subscriber, #94864)In reply to: A turning point for CVE numbers by bluca
Parent article: A turning point for CVE numbers
If you have a policy that says you need to ship fixes for all CVEs, then that's a stupid policy. It just conditions vendors to refuse each and every CVE until it goes through arbitration (something proprietary vendors already do).
What consumers of CVEs need to do is be selective, evaluate if the CVE is relevant, what are the effects of exploiting it, etc. and only then backport it to the product they ship that uses the kernel or other CVEs. Same for end users, if the bug is in an API that's not used by any software that is running, then, no, you don't have to install updates.
The problem is that all of it requires actual work, not blind adherence to the policy, and it's for security, so the business also doesn't want to spend money for it.
It's a complex problem and there are no simple solutions.
