One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.
Some of them aren’t actually bugs but just “security” people wanting to get a longer epenis by flagging issues like “maximum priority, it allows to read the ssh private key!!!1!!” And then the details are like “when typing more ./ssh/id_rsa the user private key is shown, terminal should intercept and block request”
And with LLMs it’s even worse as they’re directed to find nitpicks at all costs
The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.
Some of them are 2024 and 2025. How come they made it into this list?
Serious answer: They’re low priority bullshit rather than practical security concerns.
“This method crashes if you intentionally feed it malformed data!!”- type of stuff.
Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/
One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.
Some of them aren’t actually bugs but just “security” people wanting to get a longer epenis by flagging issues like “maximum priority, it allows to read the ssh private key!!!1!!” And then the details are like “when typing
more ./ssh/id_rsathe user private key is shown, terminal should intercept and block request”And with LLMs it’s even worse as they’re directed to find nitpicks at all costs
What’s an e-penis?
Don’t know, but I’m sure mine is bigger than yours.
Haha! Got me! :p
An e-penis is to a penis what an e-bike is to a bike.
So… you can ride it faster?
Maybe it speeds up when you twist the handle
The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.