|
|
Log in / Subscribe / Register

A turning point for CVE numbers

A turning point for CVE numbers

Posted Feb 18, 2024 16:00 UTC (Sun) by mdolan (subscriber, #104340)
Parent article: A turning point for CVE numbers

Users/vendors can pretend security bugs are not there today because there's no CVE published... but the bugs are there and they were fixed. The bad actors know this and track what changed. We know they're watching. Users/vendors not paying attention are big targets. Ivanti VPNs are an extreme, but real time example.

If you want to keep pretending and hoping, just filter the kernel CNA out. Greg has been telling everyone for a decade+ the solution is to keep updating with the LTS kernel. If you've done the engineering required to implement that process, nothing changes. If you ignored him and others and are still pretending... government regulation is here+more_coming. Like it or not, I'm sorry to say this isn't optional anymore, and it's not just going to be the kernel changing. I remember the days of happily running my own FTP+SMTP server. Things change.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds