At this point the entire concept of CVE's is just ridiculous:
0 Boosts
0 Likes
@bsdphk they're trying to force everyone to run a recent version by flooding the CVE list to work around corporate policies that don't let you run older versions with CVEs.
Rather than actually doing the legwork to evaluate which bugs might have a security impact at all, which of those are reachable in your environment, and then updating iff there is an actual risk
@bsdphk this is all the result of the Linux kernel maintainers refusing to do the work to determine whether a back ported bug fix is a security issue or not, so they just issue a CVE for every single bug fixed in a stable branch