Security News > 2021 > April > Linux kernel security uproar: What some people missed

Linux kernel security uproar: What some people missed
2021-04-27 11:47

Recently the Linux kernel community was aflame due to efforts by researchers at the University of Minnesota to intentionally torpedo Linux security by submitting faulty patches.

Organizations of all sizes have depended upon Linux for performance and security for decades; in fact, those same organizations depend upon a wide array of open source, generally.

This doesn't mean that the open source, generally, or the Linux kernel, specifically, is somehow impervious to security flaws.

If security problems aren't fixed pronto, the open source project will be labeled as lame by users, who will move on to the next option.

Later, I expressed similar thoughts, arguing that "Open source software isn't inherently more secure, rather it offers an inherently better process for securing code. Bugs in open source code, when uncovered, are quickly fixed through an open process." As such, the fact that University of Minnesota researchers were able to inject flaws into the Linux kernel isn't the real story.

Nor is the story that the kernel community caught the bad actor before the code shipped in production, though that is a real benefit of open source development practices.


News URL

https://www.techrepublic.com/article/linux-kernel-security-uproar-what-some-people-missed/#ftag=RSS56d97e7

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 17 392 2104 1389 667 4552
Kernel 4 2 8 5 0 15