Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20221223081727.GB2404@suse.de>
Date: Fri, 23 Dec 2022 09:17:28 +0100
From: Marcus Meissner <meissner@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: Details on this supposed Linux Kernel ksmbd RCE

Hi folks,

tldr: I requested 5 CVEs for the new ZDI issues Josh and Jan referenced.

long form:

Nice surprise 1 day before Christmas.

On Fri, Dec 23, 2022 at 08:06:28AM +0100, Greg KH wrote:
> On Thu, Dec 22, 2022 at 04:49:04PM -0500, Jan Schaumann wrote:
> > Lastly, given that this is a coordinated disclosure,
> > I don't know why there are no CVE IDs reserved for
> > these.
> 
> The kernel developers do not work with CVEs at all as they are not all
> that relevant for the most part for kernel issues.

We know.

> MITRE agrees with us
> will not even give them to us if we ask for them :)

Not sure why they do not like you, but to be very clear anyone else can
requests CVEs for the kernel, (except the blacklisted drivers/staging/ area).

> Some Linux companies still insist on assigning CVEs, but that's
> primarily to help enable their internal engineering processes more than
> anything else.

The whole software industry operates with CVEs as primary identifiers at
this time, so it is not just some "internal engineering processes".

> As an alternative, please look at the GSD (Global Security Database,
> https://globalsecuritydatabase.org/) for which the kernel does get ids
> assigned for issues like this, and many many others.

Perhaps this or any of the other ID spaces / databases will be taking
off in the near future, but the main industry index is CVEs at this time.


That said, I have just filed 5 CVE requests for the 5 ZDI issues cross-
referencing the Linux kernel mainline commits.

FWIW, they were fixed in mainline in July and no one had spotted them,
which of course underlines Gregs point and that there are not enough
watchers.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.