What to do about CVE numbers
What to do about CVE numbers
Posted Oct 22, 2019 8:43 UTC (Tue) by Aissen (guest, #59976)In reply to: What to do about CVE numbers by kleptog
Parent article: What to do about CVE numbers
That's not my understanding at all, I think there might be a quid pro quo in the article. I think Greg wants to identify not vulnerabilities as they are introduced, but as they are *fixed*. So the CIDs are in fact the patches that fix a vulnerability. It helps everyone know whether they are running a patched system or not, and it helps backporters know what to apply.
It seems this script does exactly that:
https://github.com/gregkh/gregkh-linux/blob/master/script...