Re: 2015 kernel CVEs

From: Josh Boyer
Date: Tue Jan 19 2016 - 12:01:12 EST


On Tue, Jan 19, 2016 at 11:57 AM, Peter Hurley <peter@xxxxxxxxxxxxxxxxxx> wrote:
> On 01/19/2016 03:28 AM, Dan Carpenter wrote:
>> I like to look back over old CVEs to see how we could do better. Here
>> is the list from 2015. I got most of this information from the Ubuntu
>> CVE tracker. Thanks Ubuntu!. If it doesn't have a hash that means it
>> might not be fixed yet.
>
> [...]
>
>> CVE-2015-4170 cf872776fc84: tty: hang in tty
>
> Makes no sense that this was assigned a CVE.
> I fixed this _2 yrs before_ it was reported and the patch was CC'd stable.

I'm guessing the CVE was assigned because there are distributions that
ship based on kernels earlier than 3.13. Those distributors need to
verify if they have the fix, etc.

josh