login
Header Space

 
 

Re: [stable] Linux 2.6.25.10

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <pageexec@...>
Cc: Greg KH <greg@...>, Andrew Morton <akpm@...>, <linux-kernel@...>, <stable@...>
Date: Tuesday, July 15, 2008 - 4:42 pm

On Tue, 15 Jul 2008, pageexec@freemail.hu wrote:

The issue is that I think it's then _misleading_ to mark that kind of 
commit specially, when I actually believe that it's in the minority.

If people think that they are safer for only applying (or upgrading to) 
certain patches that are marked as being security-specific, they are 
missing all the ones that weren't marked as such. Making them even 
_believe_ that the magic security marking is meaningful is simply a lie. 
It's not going to be.

So why would I add some marking that I most emphatically do not believe in 
myself, and think is just mostly security theater?

I generally do not remove peoples changelog entries, although I _will_ 
do even that if I think it's just too much of an actual exploit 
description (of course - the patch itself can make the exploit fairly 
clear). So you'll find CVE entries etc in the logs if you look.

But I do hope that anybody who looks for them is _aware_ that it's just a 
small minority of possible problems.

Don't get me wrong - I'm not saying that security bugs are _common_, but 
especially some local DoS thing for a specific driver or filesystem or 
whatever can be a big security problem for _somebody_.

			Linus


--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:18 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:23 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 4:42 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 5:18 pm)
Re: [stable] Linux 2.6.25.10, Rafael C. de Almeida, (Thu Jul 17, 3:19 am)
Re: [stable] Linux 2.6.25.10, , (Thu Jul 17, 3:59 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 5:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 6:08 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 7:28 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:04 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:24 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 8:56 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:23 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:00 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 9:08 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:53 pm)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Tue Jul 15, 11:27 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:33 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 9:21 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:16 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:13 am)
Re: [stable] Linux 2.6.25.10, Casey Schaufler, (Wed Jul 16, 1:26 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:21 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 1:02 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 1:13 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 10:02 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:36 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Wed Jul 16, 12:07 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Wed Jul 16, 12:16 am)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 9:30 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:16 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 8:38 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 8:51 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 9:10 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 11:13 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:01 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 10:43 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 11:43 am)
Re: [stable] Linux 2.6.25.10, Greg KH, (Wed Jul 16, 12:29 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 1:25 pm)
Re: [stable] Linux 2.6.25.10, Mike Galbraith, (Wed Jul 16, 11:43 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Wed Jul 16, 2:08 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 3:09 pm)
Re: [stable] Linux 2.6.25.10, Gabor Gombas, (Wed Jul 16, 5:35 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:04 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:41 pm)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 5:49 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:08 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:23 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 6:31 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 6:51 am)
Re: [stable] Linux 2.6.25.10, David Miller, (Wed Jul 16, 7:04 am)
Re: [stable] Linux 2.6.25.10, , (Wed Jul 16, 7:52 am)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 10:24 pm)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 11:11 pm)
speck-geostationary