当前位置:首页 > 报告详情

linux-kernel-cves-what-has-caused-so-many-to-suddenly-show-up-linuxcvedaelsdi-jiong-bi-dyags-greg-kroah-hartman-kernel-maintainer-linux-fellow.pdf

上传人: 山海 编号:627273 2025-04-21 67页 510.36KB

1、Linux Kernel Security ProcessLinux Kernel Security Processoror“Why are there so many kernel CVEs now?”Why are there so many kernel CVEs now?”Greg Kroah-Hartmangregkhlinuxfoundation.orggit.sr.ht/gregkh/presentation-securityAll of this is just my personal opinion,based on working as part of the Linux

2、kernel security team since it was created in 2005.Nothing in here reflects the opinion of the Linux Foundation or any other Linux kernel developer.But hopefully I can convince them to agree with me.Disclaimer 85,000 files38,640,000 linesKernel release 6.10.0Linux size overall 5%-10%Linux size what y

3、ou useKernel release 6.10.09 changes per hourNew*release modelRelease every 2-3 monthsAll releases are stable*As of January,2004“Cambridge promise”We will not break userspace July 2007“Cambridge promise”We will not break userspace on purpose July 2007Version numbers mean nothing2.6.x 3.x20113.x 4.x2

4、0154.x 5.x20195.x 6.x2022You are hereYou are hereDevelopers are hereDevelopers are hereStable kernel rulesBugfixLess than 100 linesNew ids or quirksMust be in Linuss tree https:/www.kernel.org/doc/html/latest/process/stable-kernel-rules.htmlhttps:/www.kernel.org/doc/html/latest/process/stable-kernel

5、-rules.html Longterm kernelsOne picked per yearMaintained for at least 2 years*4.19 5.4 5.10 5.15 6.1 6.6*sometimes longerLongterm kernels4.19 14 changes/day5.416 changes/day5.10 21 changes/day5.1524 changes/day6.129 changes/day6.633 changes/dayKernel releasesEvery release is stable17+year old guara

6、ntee to not break thingsNo fear to ever upgradeMore release information in greater detail:http:/ world has changed80%+of the worlds servers runs non-commercial distribution kernels*inter-company interactions achieve nothingThe“community”does not sign NDAs*Embedded it is like 99%,look at what is in y

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要探讨了Linux内核安全过程以及CVE(公共漏洞和暴露)在Linux内核中的角色和处理方式。作者Greg Kroah-Hartman是Linux内核安全团队的成员,他分享了从2005年起参与内核安全工作的个人见解。 关键点如下: 1. Linux内核安全团队是反应性的,而不是主动性的。 2. 内核安全团队负责处理安全漏洞,但不代表任何公司。 3. 内核安全政策:所有漏洞都可能成为“安全”问题;修复已知漏洞比放任未来问题更为合适。 4. Linux内核遵循稳定的发布周期,每2-3个月发布一次,确保稳定性和安全性。 5. 内核中的CVE数量增加,部分原因是因为更多的系统运行非商业发行版内核。 6. 硬件安全问题需要单独处理,且通常涉及跨公司、跨操作系统的协调。 7. CVE的分配是在安全修复之后进行的,通常延迟1-2周,以便系统在公开宣布前更新。 8. Linux内核现在是一个CNA(CVE认证机构),负责所有内核CVE的分配。 文章最后提到了欧洲联盟网络安全弹性法案(CRA)对Linux内核的影响,以及硬件安全问题的处理和报告流程。作者强调,在处理安全问题时,应避免在公开的commit消息中透露过多信息,以免被误用。
"Linux内核安全流程如何运作?" "为何Linux内核安全漏洞增多的原因是什么?" "如何正确报告Linux内核安全问题?"
客服
商务合作
小程序
服务号
折叠