upvote
That's nonsense. The goal is and always has been to undermine the CVE system because Greg does not believe in the system. The kernel is the only project that marks CVEs to fixes, it's the only project that considers every bug to be a "Security" bug, and it has a multi-decades long history of telling the security world to fuck off - all consistent with what I've said.

No one else has the process that the kernel has, despite plenty of people having software that's deployed in very similar ways.

There's zero question - this is ideologically motivated, not a genuine good-faith attempt to leverage the system.

reply
Or maybe it's ideologically motivated that other groups only identify certain bugs as security bugs?
reply
Make a case then. My case is that Greg has, for decades, said that he hates the CVE system and rejected it and that the kernel objectively labels CVEs based on fixes (not the standard at all, CVEs are for vulns), etc. I can point to so many objective pieces of evidence to support my claim.

You seem to have a vague, leading question. If you want to say something about "other groups" or ideologies, go ahead.

reply
Malicious compliance is compliance.
reply
I don't know what you're trying to say at all. But no, the kernel is objectively not compliant because they label fixes with CVEs and not vulnerabilities. But even if they were compliant... what would that have to do with anything? Feels like a non sequitur.

It's very hard to figure out what point you're trying to make.

reply
Every bugfix implies a bug.
reply
I'm going to graciously give you one last chance to actually say something of substance before I stop responding entirely.
reply
Haha, I was reading your comment as praise for Greg until the end
reply
> What do you mean?

No analysis is being done in the linux kernel to assess vulnerability.

> It isn't a DoS to assign every single bug fix a CVE!

On people who care about this, it is, not in the project itself though.

> Every single bug is making someone vulnerable in some way.

Not every bug is making someone vulnerable. (docs bugs, test bugs) behavioral changes, performance improvements, the list goes on.

reply