• dgdft@lemmy.world
      link
      fedilink
      English
      arrow-up
      82
      ·
      9 days ago

      Serious answer: They’re low priority bullshit rather than practical security concerns.

      “This method crashes if you intentionally feed it malformed data!!”- type of stuff.

      • jj4211@lemmy.world
        link
        fedilink
        arrow-up
        9
        ·
        8 days ago

        Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/

        One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.

    • Wispy2891@lemmy.world
      link
      fedilink
      arrow-up
      37
      ·
      edit-2
      8 days ago

      Some of them aren’t actually bugs but just “security” people wanting to get a longer epenis by flagging issues like “maximum priority, it allows to read the ssh private key!!!1!!” And then the details are like “when typing more ./ssh/id_rsa the user private key is shown, terminal should intercept and block request”

      And with LLMs it’s even worse as they’re directed to find nitpicks at all costs

    • queerlilhayseed@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      17
      ·
      9 days ago

      The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.

      Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.