From: Greg KH <greg@kroah.com>
To: oss-security@lists.openwall.com
Cc: xen-announce@lists.xen.org, xen-devel@lists.xen.org,
xen-users@lists.xen.org,
"Xen.org security team" <security-team-members@xen.org>
Subject: Re: [oss-security] Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown
Date: Tue, 24 Mar 2026 13:31:38 +0100 [thread overview]
Message-ID: <2026032405-faculty-agony-2599@gregkh> (raw)
In-Reply-To: <2026032453-departed-thrash-f153@gregkh>
On Tue, Mar 24, 2026 at 01:16:08PM +0100, Greg KH wrote:
> On Tue, Mar 24, 2026 at 12:05:44PM +0000, Xen.org security team wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA256
> >
> > Xen Security Advisory XSA-482
> > version 2
> >
> > Linux privcmd driver can circumvent kernel lockdown
> >
> > UPDATES IN VERSION 2
> > ====================
> >
> > Public release.
> >
> > ISSUE DESCRIPTION
> > =================
> >
> > The Linux kernel's privcmd driver can be abused to circumvent kernel
> > lockdown (secure boot), e.g. by modifying page tables to enable user
> > mode to modify kernel memory.
> >
> > The CNA covering Linux has refused to assign a CVE at this juncture.
>
> This is now assigned to CVE-2026-31788
And, to be more clear, the kernel CNA should have given you a CVE
earlier, sorry about that, that was my fault. We had been "burned" by
other groups/companies asking for CVEs "ahead of time" for Linux for
things that turned out to be wrong or not needing a CVE at all at the
same time you all asked for one, so I reacted much harsher here than you
all deserved by saying we would assign one once the issue was public. I
should have trusted you as obviously you know what you are doing here
and should have gotten a CVE for your accounting earlier.
Again, my fault, sorry about that, if you all need one in the future for
any issue, we will assign it ahead of time.
greg k-h
next prev parent reply other threads:[~2026-03-24 12:32 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-24 12:05 Xen Security Advisory 482 v2 - Linux privcmd driver can circumvent kernel lockdown Xen.org security team
2026-03-24 12:16 ` [oss-security] " Greg KH
2026-03-24 12:17 ` Andrew Cooper
2026-03-24 12:31 ` Greg KH [this message]
2026-03-26 12:24 ` Juergen Gross
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026032405-faculty-agony-2599@gregkh \
--to=greg@kroah.com \
--cc=oss-security@lists.openwall.com \
--cc=security-team-members@xen.org \
--cc=xen-announce@lists.xen.org \
--cc=xen-devel@lists.xen.org \
--cc=xen-users@lists.xen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.