you are viewing a single comment's thread
view the rest of the comments
[–] 45 points 5 days ago (11 children)

Some of them are 2024 and 2025. How come they made it into this list?

  • source
  • hideshow 11 child comments
  • [–] 82 points 5 days ago (1 child)

    Serious answer: They’re low priority bullshit rather than practical security concerns.

    β€œThis method crashes if you intentionally feed it malformed data!!”- type of stuff.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 9 points 4 days ago

    Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/

    One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.

  • source
  • parent
  • [–] 34 points 5 days ago* (6 children)

    Some of them aren't actually bugs but just "security" people wanting to get a longer epenis by flagging issues like "maximum priority, it allows to read the ssh private key!!!1!!" And then the details are like "when typing more ./ssh/id_rsa the user private key is shown, terminal should intercept and block request"

    And with LLMs it's even worse as they're directed to find nitpicks at all costs

  • source
  • parent
  • hideshow 6 child comments
  • [–] 5 points 5 days ago (5 children)
  • The following is my guess, I don't know what the Debian project's selection criteria for security advisories are.

    Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that's still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can't upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.

  • source
  • parent
  • [–] 2 points 5 days ago