but no, in linux cve id is assigned "on a one to two week delay from when the fix has landed in a released stable kernel version."
but no, in linux cve id is assigned "on a one to two week delay from when the fix has landed in a released stable kernel version."
"While many security people love to argue what is, or is not, a vulnerability, while dealing with CVEs, a CNA must follow the definition that cve.org gives us which is:
“An instance of one or more weaknesses in a Product that can be exploited, causing a negative impact to confidentiality, integrity, or availability; a set of conditions or behaviors that allows the violation of an explicit or implicit security policy.”
So with that definition in mind, the kernel CNA team members look at every bugfix that is added to the stable kernel releases and reviews it to determine if it meets this criteria."
So yes indeed, according to this, bugfixes are being examined for "instance of one or more weaknesses in a Product that can be exploited" - bugs.
Oh dear, oh dear.