惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Docker
C
Check Point Blog
IT之家
IT之家
Engineering at Meta
Engineering at Meta
A
About on SuperTechFans
J
Java Code Geeks
G
Google Developers Blog
博客园_首页
腾讯CDC
博客园 - Franky
F
Fortinet All Blogs
MongoDB | Blog
MongoDB | Blog
M
MIT News - Artificial intelligence
Last Week in AI
Last Week in AI
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
H
Help Net Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

LWN.net comments

tcmalloc's weird hack [LWN.net] Fixed? [LWN.net] mpd [LWN.net] Userspace AX.25 [LWN.net] RIP [LWN.net] My two cents... [LWN.net] pipx [LWN.net] Tragedy [LWN.net] A young man destined for glory [LWN.net] And 'less' won't let you search [LWN.net] A great loss [LWN.net] Sad and shocking news [LWN.net] Easy migration from Clementine [LWN.net] Sad coincidence [LWN.net] GNOME is actually usable thanks to Seth et al [LWN.net] Sad news :( [LWN.net] armhf supports preempt_rt [LWN.net] MusicBrainz accurracy [LWN.net] On open source maintainership [LWN.net] Let's stop here [LWN.net] Not a new thing [LWN.net] uv is indeed great pgmoneta Some comments on this on a Postgres blog feed [LWN.net] uv [LWN.net] going to Debian [LWN.net] Upgrading 64-bit-capable systems to 64-bit kernels? [LWN.net] Free Software foundations Maintainers can wait for code review but not for publish review? A reasonably extreme point of view [LWN.net]
Stupidity . . . or not [LWN.net]
himi · 2026-05-08 · via LWN.net comments

Quoting from the README.md on the repo:

> Because the embargo has currently been broken, no patch or CVE exists. After consultation with the
> maintainers on linux-distros@vs.openwall.org and at their request, this Dirty Frag document is being
> published. For the disclosure timeline, refer to the technical details.

In other words, the publication of this information was done in consultation with, and at the request of, the kernel and distro security groups - not something that deserves to be called "stupidity". Particularly given there's a pretty simple mitigation (blacklisting and removing the vulnerable modules).