• jj4211@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    17 hours ago

    Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.

    Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn’t a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don’t have to… They used to at least allow us a pass on “low severity” (that’s still pretty flawed), but they decided that didn’t sound “tough” enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).