• thesmokingman@programming.dev
    link
    fedilink
    English
    arrow-up
    16
    ·
    13 hours ago

    The only guaranteed fix is in the kernel. You’ll want to check your distro for the CVE. The disclosers very happily bring up all the distros affected but do not seem to have reached out to any of them to also patch. The CVE itself is still waiting for NVD analysis beyond its base score.

    I’m not actively saying they did anything wrong but I am saying they’re blowing smoke about responsible disclosure.

    • Danitos@reddthat.com
      link
      fedilink
      English
      arrow-up
      6
      ·
      9 hours ago

      They sell a vulnerability discovery program. IMO, they did this dubious responsable disclousure to get the extra marketing.

    • ozymandias117@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      12 hours ago

      Yeah… It seems like they only reached out to the kernel, and not to any distros…

      They also disclosed after 37 days rather than the more standard 90 days for everyone to patch