For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

514 points by ori_b 19 hours ago


Recent: Copy Fail - https://news.ycombinator.com/item?id=47952181 - April 2026 (466 comments)

xeeeeeeeeeeenu - 17 hours ago

For context, the author of the linked post, Sam James, is a Gentoo developer.

Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this.

It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope that the former would notify the latter, but apparently it's the responsibility of whoever finds the vulnerability.