| ▲ | pocksuppet 5 hours ago | |||||||
Did you read the CVEs? Half these aren't vulnerabilities. One allows the root user to create a kernel thread and then block its shutdown for several minutes. One is that if you do something that's obviously stupid, you don't get an event notification for it. Remember the Linux kernel's policy of assigning a CVE to every single bug, in protest to the stupid way CVEs were being assigned before that. | ||||||||
| ▲ | dspillett 4 hours ago | parent [-] | |||||||
> Did you read the CVEs? You obviously didn't read to the end of my little post, yet feel righteous enough to throw that out… > One allows the root user to create a kernel thread and then block its shutdown for several minutes. Which as part of a compromise chain could cause a DoS issue that might be able to bypass common protections like cgroup imposed limits. | ||||||||
| ||||||||