Comment by slenk

4 years ago

I guess it was Romanovsky who said it: https://lore.kernel.org/linux-nfs/YH+zwQgBBGUJdiVK@unreal/

Wait so do you disagree with ZDnet too?

Again, there's nothing that says the patches with vulnerabilities made it to stable.

Did you read the ZDnet article and look at the links that in that article in the relevant paragraph? I'm not "disagreeing", I'm saying that they are misleading the reader (and it looks like many were fooled).

The two sentences they put together are not related, but put next to each other, they make it seem like they're related. We have to be careful when reading these articles. So the researchers have made commits to stable, and the researchers have introduced vulnerabilities, but they are not referring to the same patches. So no vulnerabilities have been committed to stable.