@gregkh lol at the note.
Out of all of the consequences that could have been true, 'getting left out of academic research' was not on my bingo card.
@gregkh This is interesting:
"In addition, we find that CVE is also a focus for distributions (as they are responsible for the security of their customers). In particular, [distro] maintainers usually attach a CVE ID to indicate that the patch fixes a known security vulnerability. Interestingly, we note that the picked CVE patches appear in distributions 74.2 days earlier than LTS on average; even if the picked CVE patches are later than LTS, it is only 16.7 days later on average."
@gregkh That's odd, because CentOS' git trees are public:
- CentOS Stream 10: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10
- CentOS Stream 9: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9
@Conan_Kudo @gregkh I emailed the first author, Xingyu (xli399@ucr.edu), and they said “Centos stream was just transferred from Centos at that time.” I’ve never published a paper at a conference before, so I’d take their word for it and assumed the paper was put together a whole ago, i.e., back when all we had was Stream 8’s incomplete git history.