What would be the biggest downside if we just stopped considering severity low or medium security bugs CVE worthy?
Post
@bagder We would need to refer to bugs as "the buffer overflow that's in src/foo/bar.c line 1067 in version 4.5.6, and line 1058 in version 4.5.7" again.
Arch Linux wouldn't care, but it would make the life of Debian maintainers more difficult.
@kpcyrd countless projects basically do this already, I don't think the world would fall over. It would be fewer CVEs to care about.
@bagder I'd prefer to know what issues exist, even if it's a bit noisier (on the blue team side)
Trying not to normalise the deviance of not fixing issues at my workplace
@bagder macOS 15 still has curl 8.7.1. Those CVEs do not seem to have a lot of impact, if you ask me.
@bagder I mean CVSS is not a great scheme for ranking anyhow. Even v4 has the core problems of v3 (IMO)
@jacques we don't use CVSS, never did...
@bagder well now I just feel silly for assuming!
@jacques some background: https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/
A lot of "security researchers" would be sad that they couldn't pad their resumes with more CVE numbers ?
@bagder uhh, you sleep? that kinda seems like an upside though so it's impossible to say
@bagder Eliminating low and medium CVEs wouldn't actually make software safer; it would just blindfold defenders. It turns out that a lot of "minor" leaks can still sink the ship if they are left unmonitored.
@bagder Probably none
Attackers can sometimes chain lower severity bugs together to do something interesting, but the reality is everyone is drowning in vulnerabiliites right now
Everyone has already written off Low and Medium as "don't care"