Re: "several" CVEs in latest Debian linux security advisory DSA 6528-1
Mailing list reply defends Debian's DSA 6528-1 advisory bundling many CVEs, citing changelog review effort to limit churn.
A reply on oss-security discusses Debian advisory DSA 6528-1, which grouped numerous Linux kernel CVEs into a single update. Zdenek Salvet of Masaryk University's Institute of Computer Science argues the count reflects Debian maintainers' effort to avoid excessive churn. He notes administrators can review the Debian changelog to identify environment-relevant issues within a few hours.
- Debian advisory DSA 6528-1 bundles many Linux kernel CVEs into one update.
- Reply argues bundling limits churn; changelog review takes a few hours.
Posted by Zdenek Salvet on Sep 29 Hello, I think the number also reflects Debian maintainers' effor to avoid too much churn... You check Debian changelog to select issues most relevant to your environment reasonably quickly (in couple hours :-( ) Nothing is 100% secure, I hope we will run out of the most serious vulnerabilities soon at this pace... Regards, Zdenek Salvet salvet () ics muni cz Institute of Computer Science of...
This source does not provide full text. Read it at seclists.org.