Community notes coordination process contradicts prior kernel developer claims
2Sep 18 9:32 AM · 5d ago · 2 posts · 3 comments · 3 sources · development 2 of 3
Lobsters commenters noted that the successful coordinated embargo and pre-deployment of fixes contradicts earlier statements by Greg K-H that such a process was impractical for kernel development.
linux,security
“Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn't Greg K-H say it couldn't be done?”
> If the target is acting as an IPv6 router/gateway and adds AH in transport mode, the bug can be turned into a remote crash/DoS. With on-target memory grooming, I was able to turn it into remote root in a lab environment. > > Remote-only grooming to root is theoretically possible, but looks extremely difficult. Wow. I hope that in a few years…
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https:// thehackernews.com/2026/09/publ ic-exploits-released-for-four-linux.html
He said it couldn't be done _by core Linux developers_, and also what happened here (fixes quitely merged into public branches over the past few weeks before security writeup going public) is what he was asked to improve upon when saying that kernel devs can't do better than that.
Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn’t Greg K-H say it couldn’t be done? 🫠