oss-sec mailing list archives
Re: 432 Linux kernel CVEs
From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Fri, 24 Jul 2026 08:24:30 -0700
On 7/24/2026 3:20 AM, John Haxby wrote:
And I don't care if you say you have a kernel with a formal proof -- you'll still have bugs in somewhere in the application stack.
Or in the hardware its run on - formal proofs didn't defend from Spectre
and Meltdown when we all learned that CPUs did things differently than
our models of them assumed they did, and the proof of an OS is unlikely
to cover all the code running in the firmware of the underlying devices.
--
-Alan Coopersmith- alan.coopersmith () oracle com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Current thread:
- Re: 432 Linux kernel CVEs, (continued)
- Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 21)
- Re: 432 Linux kernel CVEs Jan Schaumann (Jul 21)
- Re: 432 Linux kernel CVEs Greg KH (Jul 22)
- Re: 432 Linux kernel CVEs Peter Gutmann (Jul 21)
- Re: 432 Linux kernel CVEs Stephan Verbücheln (Jul 22)
- Re: 432 Linux kernel CVEs Marcus Meissner (Jul 22)
- Re: 432 Linux kernel CVEs Loganaden Velvindron (Jul 27)
- Re: 432 Linux kernel CVEs David A. Wheeler (Jul 22)
- Re: 432 Linux kernel CVEs Peter Gutmann (Jul 23)
- Re: 432 Linux kernel CVEs John Haxby (Jul 24)
- Re: 432 Linux kernel CVEs Alan Coopersmith (Jul 24)
- Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 24)
- Re: 432 Linux kernel CVEs Jan Schaumann (Jul 21)
- Re: 432 Linux kernel CVEs Demi Marie Obenour (Jul 25)
- Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 21)
- Re: 432 Linux kernel CVEs Steffen Nurpmeso (Jul 22)
