Re: [PATCH RFC 6.6.y 00/15] Some missing CVE fixes

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed 2024-10-02 09:26:46, Jens Axboe wrote:
> On 10/2/24 9:05 AM, Vegard Nossum wrote:
> > Christophe JAILLET (1):
> >   null_blk: Remove usage of the deprecated ida_simple_xx() API
> > 
> > Yu Kuai (1):
> >   null_blk: fix null-ptr-dereference while configuring 'power' and
> >     'submit_queues'
> 
> I don't see how either of these are CVEs? Obviously not a problem to
> backport either of them to stable, but I wonder what the reasoning for
> that is. IOW, feels like those CVEs are bogus, which I guess is hardly
> surprising :-)

"CVE" has become meaningless for kernel. Greg simply assigns CVE to
anything that remotely resembles a bug.

Best regards,
								Pavel
-- 
DENX Software Engineering GmbH,        Managing Director: Erika Unter
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany

Attachment: signature.asc
Description: PGP signature


[Index of Archives]     [Linux Kernel]     [Kernel Development Newbies]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite Hiking]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux