top | item 39372499

A turning point for CVE numbers

4 points| Ambroisie | 2 years ago |lwn.net

1 comment

order

theamk|2 years ago

Relevant quote:

> anything that looks like a bug fix — meaning many of the changes that find their way into the stable kernel updates — will have a CVE number assigned to it. Bear in mind that, as of 6.1.74, the 6.1 kernel (which has been out for just over one year) has had 12,639 fixes applied to it. The 4.19 kernel, as of 4.19.306, has had 27,952. Not all of these patches will get CVE numbers, but many will.

"it is going to be interesting to watch; popcorn is recommended" indeed!