oss-sec mailing list archives
Re: linux-distros list policy and Linux kernel, again
From: "Eduardo' Vela\" <Nava>" <evn () google com>
Date: Sun, 27 Aug 2023 20:56:12 +0200
On Sun, 27 Aug 2023, 19:41 Demi Marie Obenour, <demi () invisiblethingslab com> wrote:
Does this include unfixed vulnerabilities?
The link* has more details, but briefly, deduplication is done by fix commit. Efforts to fix unfixed Syzkaller crashes (also something being worked on) are complementary to the effort to generate CVE identifiers for them, if that's your question (so, yes? Unfixed vulnerabilities found by Syzkaller are meant to be fixed first and then a CVE is generated for the reports fixed by their corresponding Fix commit). Generating CVEs for Syzkaller reports without deduplicating them first would be disruptive and useless (the link* goes into more details). Deduplication is subjective as it depends on how the bugs are understood. The analysis that is needed to deduplicate is happening as part of the fix review process. One could, of course, create a different mechanism to automatically (or semi-automatically) deduplicate Syzkaller reports and accept the risk of duplicate CVEs. This may be something to look at in the future, but it's not what's being worked on for the first iteration, and we probably will have a lot to fix and learn from even after the first wave of CVEs are generated. * https://github.com/google/cvelist/tree/cve-automation/fuzzer
Current thread:
- linux-distros list policy and Linux kernel, again Solar Designer (Aug 25)
- Re: linux-distros list policy and Linux kernel, again Seth Arnold (Aug 25)
- Re: linux-distros list policy and Linux kernel, again Demi Marie Obenour (Aug 26)
- Re: linux-distros list policy and Linux kernel, again Solar Designer (Aug 26)
- Re: linux-distros list policy and Linux kernel, again Eduardo' Vela" <Nava> (Aug 27)
- Re: linux-distros list policy and Linux kernel, again Demi Marie Obenour (Aug 27)
- Re: linux-distros list policy and Linux kernel, again Eduardo' Vela" <Nava> (Aug 27)
- Re: linux-distros list policy and Linux kernel, again Demi Marie Obenour (Aug 28)
- Re: linux-distros list policy and Linux kernel, again Seth Arnold (Aug 25)
- Re: linux-distros list policy and Linux kernel, again Solar Designer (Aug 28)
- Re: linux-distros list policy and Linux kernel, again Jeremy Stanley (Aug 28)
- Re: linux-distros list policy and Linux kernel, again Willy Tarreau (Aug 28)
- Re: linux-distros list policy and Linux kernel, again Solar Designer (Aug 30)
- Re: linux-distros list policy and Linux kernel, again Willy Tarreau (Sep 04)
- Re: linux-distros list policy and Linux kernel, again Solar Designer (Sep 08)