Conversation

Vlastimil Babka

me, sobbing: "you can't just point at every stable commit working around a sanitizer false positive and call it a CVE"
them, pointing at KCSAN data_race() annotation: "CVE"
3
0
12
@vbabka I hope someone at MITRE has enough common sense not to let Greg sabotage CVE's like this for much longer :-(. @gregkh
1
0
3
@pavel @gregkh ok this one was ultimately rejected, good.
0
0
2
@vbabka Hey, we get some wrong, I thought this was a real "BUG" output, which would have deserved a CVE. Now rejected, if you notice us messing things up at times, let us know! We've already rejected a bunch, here's our current stats after just a few weeks doing this:

Year Reserved Assigned Rejected Total
2019: 47 2 1 50
2020: 37 13 0 50
2021: 45 205 0 250
2022: 45 5 0 50
2023: 51 145 4 200
2024: 502 48 0 550
Total: 727 418 5 1150

Majority so far is back-filling in from the GSD entries. We've only really done 2-3 stable releases so far, we have a bunch of review to catch up with, you can see the current status in our git repo if people are curious what is being discussed/reviewed.
0
1
3