kvm.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [RESEARCH] Patch delivery delay
@ 2015-09-14  8:58 Stefan Geißler
  2015-09-14 15:13 ` Paolo Bonzini
  0 siblings, 1 reply; 4+ messages in thread
From: Stefan Geißler @ 2015-09-14  8:58 UTC (permalink / raw)
  To: kvm

Hello all,

I am currently analyzing the delay between vulnerability disclosure (CVE 
release) and the release of a corresponding patch.

Firstly, i noticed that some vulnerabilities are patched before the CVE 
was assigned. How is that possible? Was the vulnerability "accitendally" 
fixed? (Example: According to NVD CVE-2013-1943 was fixed on 2011-05-22)

Second, does someone know why some vulnerabilities get a fix on CVE 
release day while some only recieve a fix after weeks or even month? 
(Maximum delay I observed is 183 days)

Regards,
Stefan

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2015-09-14 20:24 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-09-14  8:58 [RESEARCH] Patch delivery delay Stefan Geißler
2015-09-14 15:13 ` Paolo Bonzini
2015-09-14 18:59   ` Stefan Geißler
2015-09-14 20:24     ` Paolo Bonzini

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).