you are viewing a single comment's thread
view the rest of the comments
[–] 24 points 4 months ago (2 children)

Ubuntu is one of the most used distros in both desktop and server environments. Take down the update servers, can’t patch CopyFail. Can’t patch CopyFail, more time to access affected systems.

That’s my paranoid take anyway.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 11 points 4 months ago (3 children)

    Normally patches roll out before the vulnerability is disclosed. But I honestly don't know the status on CopyFail

  • source
  • parent
  • hideshow 6 child comments
  • [–] 7 points 4 months ago (2 children)

    Most distros delivered patched kernels well before the vulnerability was publicly disclosed. Not sure if Ubuntu did but they had ample time to do so.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 5 points 4 months ago (1 child)

    Not true. None of the major distros were alerted and Ubuntu, Debian, RHEL, etc. were all struggling at the last minute. See: https://infosec.exchange/@wdormann/116489443704631952

    However, none of those DDoS's took out the archive servers, so Ubuntu users could still get new kernels.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 4 months ago (1 child)

    Interesting. So only the fast distros were done patching by time of disclosure. The ones you wouldn't run a server on. Because only the kernel devs better informed. That's... pretty amateurish from the guys who discovered CopyFail.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 3 points 4 months ago* (last edited 1 month ago) (1 child)