Linux Is a CVE Numbering Authority (CNA)
kroah.com
kroah.com
If you use the newest released kernel of a supported branch, by definition you have no open CVEs (except those that other organizations manage to get assigned).
If you use something older, you will have many open CVEs.
Basically saying that the CVE system is useless without saying it.
Do you have a citation for this?
For a CNA to submit CVEs they need to submit a CVSS score, initially 100% of their scores will be audited, if the score is 0, it would be considered an invalidly assigned CVE. Issues assigned a CVE must be exploitable by someone who does not already have access to do the thing described, they also must have documented impact to the confidentiality, integrity or availability of the impacted system. All of this means Linux being a CNA should not result in an increase of CVEs in unless they are already not getting CVEs for those vulnerabilties.
> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify.