|
|
Message-ID: <aru6MwcXY0NMwMey@netmeister.org> Date: Tue, 29 Sep 2026 09:16:35 -0400 From: Jan Schaumann <jschauma@...meister.org> To: oss-security@...ts.openwall.com Subject: "several" CVEs in latest Debian linux security advisory DSA 6528-1 Hi, https://lists.debian.org/debian-security-announce/2026/msg00441.html notes that: "Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks." Where "several" is a list of 1,313 CVE IDs. I understand that this is a result of the Linux kernel team assigning a CVE ID for virtually any change combined with the onslaught of AI assisted findings, but I think a security advisory of this sort serves no meaningful purpose and illustrates the argument that it's pointless for defenders to attempt to track and assess individual vulnerabilities. At the same time, automatically and frequently pulling and applying all updates without scrutiny isn't really an option for large scale, multi-purpose environments either -- many of the vulnerabilities will not apply to them at all, and the churn may introduce other problems. The only reasonable approach I see is to hunker down, do all the basics that should have been done before (disable unused modules, don't use containers as a reliable security boundary, reduce attack surface, ...), but at this point I've come to believe that multi-user linux systems may effectively no longer be viable, as a LPE ought to be assumed. I don't know how everybody else approaches this shift. -Jan
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.