[{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3824890298","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3824890298","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3824890298,"node_id":"IC_kwDOLyuXf87j-zG6","user":{"login":"todb","id":24144,"node_id":"MDQ6VXNlcjI0MTQ0","avatar_url":"https://avatars.githubusercontent.com/u/24144?v=4","gravatar_id":"","url":"https://api.github.com/users/todb","html_url":"https://github.com/todb","followers_url":"https://api.github.com/users/todb/followers","following_url":"https://api.github.com/users/todb/following{/other_user}","gists_url":"https://api.github.com/users/todb/gists{/gist_id}","starred_url":"https://api.github.com/users/todb/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/todb/subscriptions","organizations_url":"https://api.github.com/users/todb/orgs","repos_url":"https://api.github.com/users/todb/repos","events_url":"https://api.github.com/users/todb/events{/privacy}","received_events_url":"https://api.github.com/users/todb/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-30T17:41:00Z","updated_at":"2026-01-30T17:41:00Z","body":"CVSS scores for libraries and other shared components that aren't just regular client or server applications is always fraught, since they cannot really be applied sensibly to real-world implementations.\n\nBeing able to articulate severity -- especially from a third-party point of view -- is still desirable, but I'm not convinced that CVSS is the way to do it.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3824890298/reactions","total_count":2,"+1":2,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3824962683","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3824962683","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3824962683,"node_id":"IC_kwDOLyuXf87j_Ex7","user":{"login":"todb","id":24144,"node_id":"MDQ6VXNlcjI0MTQ0","avatar_url":"https://avatars.githubusercontent.com/u/24144?v=4","gravatar_id":"","url":"https://api.github.com/users/todb","html_url":"https://github.com/todb","followers_url":"https://api.github.com/users/todb/followers","following_url":"https://api.github.com/users/todb/following{/other_user}","gists_url":"https://api.github.com/users/todb/gists{/gist_id}","starred_url":"https://api.github.com/users/todb/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/todb/subscriptions","organizations_url":"https://api.github.com/users/todb/orgs","repos_url":"https://api.github.com/users/todb/repos","events_url":"https://api.github.com/users/todb/events{/privacy}","received_events_url":"https://api.github.com/users/todb/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-30T18:00:27Z","updated_at":"2026-01-30T18:00:43Z","body":"That said -- CISA-ADP isn't editing the CNA portion of the record directly. Downstream customers can choose to use, or ignore, the ADP container for additional insight. Yes, it's an authority, being CISA and all, but downstream users can take the ADP suggestions, or leave them.\n\nThe concern is totally valid and I'm not speaking on behalf of CISA. If anything, I'm speaking on behalf of the CVE Board. It's a good call out. I can bring it up with the rest of CVE Board.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3824962683/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3825093730","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3825093730","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3825093730,"node_id":"IC_kwDOLyuXf87j_kxi","user":{"login":"003random","id":22357749,"node_id":"MDQ6VXNlcjIyMzU3NzQ5","avatar_url":"https://avatars.githubusercontent.com/u/22357749?v=4","gravatar_id":"","url":"https://api.github.com/users/003random","html_url":"https://github.com/003random","followers_url":"https://api.github.com/users/003random/followers","following_url":"https://api.github.com/users/003random/following{/other_user}","gists_url":"https://api.github.com/users/003random/gists{/gist_id}","starred_url":"https://api.github.com/users/003random/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/003random/subscriptions","organizations_url":"https://api.github.com/users/003random/orgs","repos_url":"https://api.github.com/users/003random/repos","events_url":"https://api.github.com/users/003random/events{/privacy}","received_events_url":"https://api.github.com/users/003random/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-30T18:33:20Z","updated_at":"2026-01-30T18:37:07Z","body":"CVSS is about scoring 'common' vulnerabilities, so it is expected that a score does not represent every environment.\n\nI would suggest the use of CVSS 4.0, as it comes with the `Attack Requirements (AT)` metric, which allows for a signal that the vulnerability might not be exploitable across all deployments. Users can set the Modified Base Metrics if the vulnerability behaves differently in their environment, or if environmental prerequisites are met (MAT:N).\n\nAdditionally, if the vendor wants to signal a different urgency than a generic score portraits, then the CVSS 4.0 `Provider Urgency (U)` metric can also be set.\n\nAt last, the CVE description of the vulnerability is a very important place to add details in an easy to understand manner. Especially if no CVSS or CWE values are provided. My suggestion would be to leave out the stack traces and include the details that normally require `deep kernel expertise`, and explain the environmental constraints. This makes it for every downstream consumer, including CISA, easier to correctly backfill the data without causing harm.\n\n\nFor clarity: this is my perspective as a downstream consumer and enrichment provider (I’m the co-founder of Volerion.com). I have no association with CISA, and this is not an official CISA position.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3825093730/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3825698669","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3825698669","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3825698669,"node_id":"IC_kwDOLyuXf87kB4dt","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-30T20:57:42Z","updated_at":"2026-01-30T20:57:42Z","body":"We (i.e. the Linux kernel CVE team) have NO IDEA HOW LINUX IS USED, nor does any other open source project, and as such, can not assign CVSS scores reliably to any of our CVE entries.  It's all up to the user who takes our code and does something with it to be able to properly decide this.\n\nAs such, even attempting for anyone to assign a generic CVSS score just will not work at all.  Remember, Linux is in so many different things like air traffic control systems, network switches, cell towers, cellular modem in the iphone, cameras, TVs, camera processor in a cell phone, desktops, servers, stock exchanges, power meters, A/C systems, billions of Android phones, laptops, satellites, super yacht ballast systems, GPS navigation systems, stone cutting machines, naval battleships, self-driving cars, laser welding robots, credit card processing terminals, and of course automatic cow milking machines. So please, stop attempting to score kernel.org CVEs, as it gives people a false sense that someone else already reviewed the issue for their use case.\n\nIf you do wish to do this for the \"common\" Linux use case, then you must ONLY do this for the Android use case, as that is in the billions.  Every other use case of Linux is just a rounding error.  But note, the Android security team already does this work for their users, so please don't attempt to duplicate the great work they are already doing, that would just be foolish.\n\nDue to our high volume (13 CVEs / day), we can not \"add details in an easy to understand manner\", as that does not scale on our side.  It is up to each user of our software to do that on their own, just like for any open source software that they use.  We provide the signal which they can use to automatically filter out CVEs that DO NOT affect them (using the files affected and git/version range json fields), so that they can properly focus on the CVEs that DO affect them.  Those they can easily triage on their own with the user's specific use-case knowledge. ","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3825698669/reactions","total_count":3,"+1":3,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3826043755","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3826043755","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3826043755,"node_id":"IC_kwDOLyuXf87kDMtr","user":{"login":"karelorigin","id":20503272,"node_id":"MDQ6VXNlcjIwNTAzMjcy","avatar_url":"https://avatars.githubusercontent.com/u/20503272?v=4","gravatar_id":"","url":"https://api.github.com/users/karelorigin","html_url":"https://github.com/karelorigin","followers_url":"https://api.github.com/users/karelorigin/followers","following_url":"https://api.github.com/users/karelorigin/following{/other_user}","gists_url":"https://api.github.com/users/karelorigin/gists{/gist_id}","starred_url":"https://api.github.com/users/karelorigin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/karelorigin/subscriptions","organizations_url":"https://api.github.com/users/karelorigin/orgs","repos_url":"https://api.github.com/users/karelorigin/repos","events_url":"https://api.github.com/users/karelorigin/events{/privacy}","received_events_url":"https://api.github.com/users/karelorigin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-30T22:17:12Z","updated_at":"2026-01-30T22:51:37Z","body":"@gregkh,\n\nCan you explain to me how the **technical impact** of a DoS vulnerability differs between a thermostat and a desktop computer? It seems to me like you are addressing the fact that various use-cases may have different real-world impacts, which are not measured by CVSS. The same can be said of your objections to weakness enumeration (CWE), which simply defines what the vulnerability is and also has no relation to specific Linux kernel environments. Furthermore, assuming it is done correctly, enrichment for either of these standards objectively never carries a downside for consumers: more data points to base decisions on.\n\nAll other (exploitability) metrics are scored from a generic point of view, independent of specific implementations, as is the case with vulnerabilities in libraries: [CVSS 4.0 User Guide](https://www.first.org/cvss/v4.0/user-guide#:~:text=When%20assessing%20the%20impact%20of%20a%20vulnerability%20in%20a%20library%2C%20independent%20of%20any%20adopting%20program%20or%20implementation%2C%20the%20analyst%20will%20often%20be%20unable%20to%20take%20into%20account%20the%20ways%20in%20which%20the%20library%20might%20be%20used). These metrics may then be customized by consumers through [Modified Base Metrics](https://www.first.org/cvss/v4.0/specification-document#:~:text=These%20metrics%20enable%20the%20consumer%20analyst%20to%20override%20individual%20Base%20metric%20values%20based%20on%20specific%20characteristics%20of%20a%20user%E2%80%99s%20environment.%20Characteristics%20that%20affect%20Exploitability%20or%20Impact%20can%20be%20reflected%20via%20an%20appropriately%20modified%20Environmental%20metric%20value.) to match their specific environments/implementations.\n\n> If you do wish to do this for the \"common\" Linux use case\n\nYou are misinterpreting the original post; it does not require you to guess how Linux might be used, it simply explains that environmental constraints may be reflected within a CVSS 4.0 vector via Attack Requirements (AT), and that consumers can (re)define these conditions as met by setting the Modified Attack Requirements (MAT) metric. The only thing CVSS asks of you is to simply point out that these constraints **exist**: e.g. only systems on CPU architecture XYZ are affected.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3826043755/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3826677511","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3826677511","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3826677511,"node_id":"IC_kwDOLyuXf87kFncH","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-31T00:22:07Z","updated_at":"2026-01-31T00:22:07Z","body":"@todb  - Agreed that CVSS struggles with anything that isn't a straightforward client/server app. And yes, technically downstream consumers can ignore the ADP container, but in practice that's not what happens. Most vulnerability management tools and security teams treat CISA scores as authoritative - they don't have the context or expertise to second-guess them, so they just use whatever shows up. The \"you can ignore it\" escape hatch exists in theory but not in practice.\n\n@003random - CVSS 4.0's AT metric is a step in the right direction, but it still assumes you can meaningfully express \"this might not be exploitable everywhere\" as a single modifier. For the kernel, it's not a matter of \"some environments might be safe\" - it's that the same CVE might be critical, medium, or completely irrelevant depending on architecture, config, workload, and what mitigations are compiled in. That's not environmental modification territory, that's \"this needs separate scores per deployment class\" territory.\n\nWe can keep going back and forth on CVSS 3.1 vs 4.0 semantics, or how consumers are theoretically supposed to enrich scores for their environments, but let's step back to what's actually happening: most kernel CVEs end up with a generic 5.5 score and a CWE that may or may not reflect the actual bug. We're assigning over 100 CVEs per week. Neither we, nor CISA, nor NVD have the resources to do the kind of deep analysis that would make these scores meaningful. The volume simply doesn't allow for it. If individual consumers - distros, cloud providers, device manufacturers want to do proper contextual scoring for their deployments, that's great, we encourage it. But WE can't do it at scale, and we're asking that other groups stop pretending they can. Publishing generic scores that look authoritative but aren't doesn't help anyone.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3826677511/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3827636306","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3827636306","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3827636306,"node_id":"IC_kwDOLyuXf87kJRhS","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-31T06:12:57Z","updated_at":"2026-01-31T06:12:57Z","body":"> Can you explain to me how the technical impact of a DoS vulnerability differs between a thermostat and a desktop computer? \n\nNo, I can not, and neither can you :)\n\nWe don't know if a CVE, which we assigned because it is a DoS fix for some situations, is a DoS fix for everyone.  For some users it might be, for others, it is impossible for those situations to ever happen so there was no fix at all as it never was a DoS.\n\nAs Ben Hawkes said so well:\n    “It’s hard to capture the fact that a bug can be super serious in one type of deployment,\n    somewhat important in another, or no big deal at all – and that the bug can be all of this\n    at the same time. Vulnerability remediation is hard.” \n\n  https://blog.isosceles.com/what-is-a-good-linux-kernel-bug/\n\nAs Sasha says, if you put ANYTHING in that field, people will treat it as \"oh, that's the value for me!\", which is NOT the case at all.  The integrator of our software MUST be doing this type of review and determine the severity themselves, it is impossible for you, or anyone else, to do that for all users of Linux.\n\nCISA is now recommending that NO CVSS/CWE scores be used at all, please follow their guidelines so that no one is confused anymore, AND more users will actually update properly.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3827636306/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3827879709","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3827879709","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3827879709,"node_id":"IC_kwDOLyuXf87kKM8d","user":{"login":"adulau","id":3309,"node_id":"MDQ6VXNlcjMzMDk=","avatar_url":"https://avatars.githubusercontent.com/u/3309?v=4","gravatar_id":"","url":"https://api.github.com/users/adulau","html_url":"https://github.com/adulau","followers_url":"https://api.github.com/users/adulau/followers","following_url":"https://api.github.com/users/adulau/following{/other_user}","gists_url":"https://api.github.com/users/adulau/gists{/gist_id}","starred_url":"https://api.github.com/users/adulau/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/adulau/subscriptions","organizations_url":"https://api.github.com/users/adulau/orgs","repos_url":"https://api.github.com/users/adulau/repos","events_url":"https://api.github.com/users/adulau/events{/privacy}","received_events_url":"https://api.github.com/users/adulau/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-01-31T08:32:50Z","updated_at":"2026-01-31T08:32:50Z","body":"CVSS is so perspective-dependent and volatile that having multiple scores (CVSS, SSVC, or others) reflecting the developer, user, and CSIRT perspectives makes far more sense than relying on a single “CVSS to rule them all.\"","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3827879709/reactions","total_count":2,"+1":2,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3880754215","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3880754215","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3880754215,"node_id":"IC_kwDOLyuXf87nT5wn","user":{"login":"chandanbn","id":3230302,"node_id":"MDQ6VXNlcjMyMzAzMDI=","avatar_url":"https://avatars.githubusercontent.com/u/3230302?v=4","gravatar_id":"","url":"https://api.github.com/users/chandanbn","html_url":"https://github.com/chandanbn","followers_url":"https://api.github.com/users/chandanbn/followers","following_url":"https://api.github.com/users/chandanbn/following{/other_user}","gists_url":"https://api.github.com/users/chandanbn/gists{/gist_id}","starred_url":"https://api.github.com/users/chandanbn/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/chandanbn/subscriptions","organizations_url":"https://api.github.com/users/chandanbn/orgs","repos_url":"https://api.github.com/users/chandanbn/repos","events_url":"https://api.github.com/users/chandanbn/events{/privacy}","received_events_url":"https://api.github.com/users/chandanbn/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-10T21:15:08Z","updated_at":"2026-02-11T18:59:36Z","body":"Completely agree (1) there is no one-size-fits-all, and (2) it would be unreasonable for the Linux security team to analyze and score every bug, as (3) it is unreasonable consumers (IT operators, system integrators) to throughly analyze every bug to determine the potential impact on their environment. Acknowledging that CISA or whoever vulnriching is doing a service to take this burden off both ends, but not an easy task. The best approach is simply take the bug-fix, recompile, and deploy, but that is easier said than done.\n\nTrying to isolate the problem by taking out subjectivity to bring some clarity here:\n\n0. Ignore CVSS 3 or 2 that are obsolete.\n1. CVSS 4 introduces the classic abstraction of a “[system](https://www.first.org/cvss/v4.0/faq#What-are-the-boundaries-between-a-Vulnerable-System-and-Subsequent-System)” (aka “the product” in question). Start scoring with respect to the Linux Kernel only. Everything else is outside the system (hardware, apps, user-land, libraries), and assume it is in perfect working order with no other vulnerabilities or weaknesses.\n\n<img width=\"1024\" height=\"559\" alt=\"Image\" src=\"https://github.com/user-attachments/assets/6f655490-038b-45a9-b86f-a3e64ef8f521\" />\n\n2. Consider everything in that is part of the kernel source is enabled and running. Ignore that parts can be turned off, unloaded, or not compiled at all.\n3. Determine CVSS metrics that are inherent constants across to all deployment use cases, easy to determine, or indisputable:  \n    -  Vulns in network-facing drivers or protocol stacks --> AV:N, anything that requires executing code locally --> AV:L.\n    - Vulnerable System Confidentiality = can a hacker read kernel memory?\n    - Vulnerable System Integrity = can a hacker write to kernel memory?\n    - Vulnerable system Availability = can a hacker turn off the system or parts of it?\n 4. What remains then are likely the Subsequent System Impacts. These are hard to determine because of the diverse set “subsequent systems” that interact wit the operating system as reiterated by others on this thread.\n     - For each of the most common deployment scenarios (Android, Containers, IoT/OT, Workstations/Desktops) determine what the most “[reasonable worst-case](https://www.first.org/cvss/specification-document#:~:text=reasonable%20worst%2Dcase)” (as in CVSS spec) impact may be. Use the metadata provided by kernel CNA like affected files and versions to determine the applicability (automate it).\n6. Add them as separate CVSS 4 scores to your enriched CVE record noting the \"scenario\" and assumptions made. CVE record does allow providing multiple scores based on common deployment situations exactly for cases like this.\n\nThe most difficult and contentious part of this process is step 4. As a solution, I suggest just pick top three most common deployment situations: Mobile, Container, IoT. Pick one or two representative products in each class - Not perfect but something is better than nothing. This will likely cater to more than 90% of use cases. \n\n**TLDR;** Enrichers, please don't provide just one score, but provide three: one for Android, one for Cloud workload Linux VMs/containers (Ubuntu, Alpine?) and one for IoT (Raspberry Pi, Yocto, OpenWRT?).","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3880754215/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3882544561","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3882544561","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3882544561,"node_id":"IC_kwDOLyuXf87nau2x","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T06:25:33Z","updated_at":"2026-02-11T06:25:33Z","body":"No, do NOT attempt to give scores for any specific use case as you don't really know how those use cases work.  Let the Android team properly review and score for their use case, same for any random embedded or server use case (as is already happening today.)\n\nAnd a container does NOT contain a kernel, so I don't think any container information makes sense :)\n\nAgain, just we are asking for no scoring to happen, that is up to the vendor/user of the software, NOT the producer of the software as we can not, and do not, dictate use, nor do we know how our software is used in the overall system, which affects directly how anything can ever be \"scored\".","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3882544561/reactions","total_count":2,"+1":2,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3883139369","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3883139369","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3883139369,"node_id":"IC_kwDOLyuXf87ndAEp","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T09:02:36Z","updated_at":"2026-02-11T09:02:36Z","body":"Again, we do not know what a \"user perspective\" is here at all.  Nor do we know what a \"CSIRT perspective\" is.\n\nA \"developer perspective\" makes no sense as developers just fix bugs and tell you to always update to the latest release, so if you want that perspective, I'll just mark every CVE as a \"9.9\" to get people to do that :)\n","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3883139369/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3884999106","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3884999106","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3884999106,"node_id":"IC_kwDOLyuXf87nkGHC","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T14:59:18Z","updated_at":"2026-02-11T14:59:18Z","body":"@chandanbn which Android? the one that runs on my phone? the ones that runs in my car? or the ones that NASA uses as PhoneSats?\n\nCompletely different usecases, completely different scores. This just doesn't work.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3884999106/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3885582116","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3885582116","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3885582116,"node_id":"IC_kwDOLyuXf87nmUck","user":{"login":"attritionorg","id":3095424,"node_id":"MDQ6VXNlcjMwOTU0MjQ=","avatar_url":"https://avatars.githubusercontent.com/u/3095424?v=4","gravatar_id":"","url":"https://api.github.com/users/attritionorg","html_url":"https://github.com/attritionorg","followers_url":"https://api.github.com/users/attritionorg/followers","following_url":"https://api.github.com/users/attritionorg/following{/other_user}","gists_url":"https://api.github.com/users/attritionorg/gists{/gist_id}","starred_url":"https://api.github.com/users/attritionorg/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/attritionorg/subscriptions","organizations_url":"https://api.github.com/users/attritionorg/orgs","repos_url":"https://api.github.com/users/attritionorg/repos","events_url":"https://api.github.com/users/attritionorg/events{/privacy}","received_events_url":"https://api.github.com/users/attritionorg/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T16:35:03Z","updated_at":"2026-02-11T16:35:03Z","body":"> No, do NOT attempt to give scores for any specific use case as you don't really know how those use cases work. Let the Android team properly review and score for their use case, same for any random embedded or server use case (as is already happening today.)\n> \n> And a container does NOT contain a kernel, so I don't think any container information makes sense :)\n> \n> Again, just we are asking for no scoring to happen, that is up to the vendor/user of the software, NOT the producer of the software as we can not, and do not, dictate use, nor do we know how our software is used in the overall system, which affects directly how anything can ever be \"scored\".\n\nThe Kernel team loves to remind everyone that the kernel is used in everything from a desktop to a satellite to a whatever. While true, this notion of \"let the user score\" is then thrusting that responsibility downstream to all 293482938 of their consumers. Unfortunately, in the real world, that just doesn't happen 99% of the time. Teams are already buried in disclosures, a big thanks to Kernel and Patchstack alone, and need some type of guidance to figure out risk. CVSS is far from perfect, we all agree on that, but it is basically the industry standard for this like it or not. Saying \"just score it all as 9.9\" to force people to upgrade is also tone-deaf to Kernel's big bold claim of it being used in said devices. Sure, just upgrade that satellite to the newest version! Then do it again a week later! And the next week! Seriously, do you think that's possible? How about a 'smart' device in a home or even the personal routers a lot of us use? It just is not happening. Kernel needs to get their heads out of their laptops and consider how consumers triage vulnerabilities and the viability of upgrading all those devices however often a new Kernel version is released.\n\nFind a solution that is somewhere between \"we don't want to do any actual work\" and \"what will consumers reasonably do\". Hell, most wouldn't update their Windows machines if it wasn't forced on them these days, something Microsoft chose to do. It's annoying, but one reboot every month is that middle-ground for them. Like it or not, Kernel is seen as a junk CNA because of the laughable entries they spew out.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3885582116/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3885822645","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3885822645","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3885822645,"node_id":"IC_kwDOLyuXf87nnPK1","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T17:18:23Z","updated_at":"2026-02-11T17:18:23Z","body":"Yes, I do think it is possible to properly vet the kernel cve \"flood\" for a specific device and use case by a single team/engineer and properly push updates out to devices in the real world when needed.  As proof, we have been doing so quite regularly over the past years for a few billion devices in some Linux use cases.\n\nIf a user of Linux does not wish to do the vetting/review for their specific use case of the software, then I'm sure their supplier will be glad to do so (as that is what they pay them for.)  Again, that has been happening quite well for many years in many industries already, so it can be done.\n\nBut as a developer of an open source software package, with no insight as to how it is used, nor even what portions of the software is used, it is impossible for us to give any sort of a \"score\" to a vulnerability report.  That statement has been backed up by many others in the past, it is not just our opinion.\n\nMicrosoft \"cheats\" on this as they define the use case AND they only report a specific level of vulnerability to the public.\n\nSorry you feel we are a junk CNA, if you have specific issues with our being a CNA, please report them to us or to cve.org and we will be glad to address them.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3885822645/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3886240439","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3886240439","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3886240439,"node_id":"IC_kwDOLyuXf87no1K3","user":{"login":"attritionorg","id":3095424,"node_id":"MDQ6VXNlcjMwOTU0MjQ=","avatar_url":"https://avatars.githubusercontent.com/u/3095424?v=4","gravatar_id":"","url":"https://api.github.com/users/attritionorg","html_url":"https://github.com/attritionorg","followers_url":"https://api.github.com/users/attritionorg/followers","following_url":"https://api.github.com/users/attritionorg/following{/other_user}","gists_url":"https://api.github.com/users/attritionorg/gists{/gist_id}","starred_url":"https://api.github.com/users/attritionorg/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/attritionorg/subscriptions","organizations_url":"https://api.github.com/users/attritionorg/orgs","repos_url":"https://api.github.com/users/attritionorg/repos","events_url":"https://api.github.com/users/attritionorg/events{/privacy}","received_events_url":"https://api.github.com/users/attritionorg/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T18:40:50Z","updated_at":"2026-02-11T18:40:50Z","body":"> If a user of Linux does not wish to do the vetting/review for their specific use case of the software, then I'm sure their supplier will be glad to do so (as that is what they pay them for.) Again, that has been happening quite well for many years in many industries already, so it can be done.\n\nIt's really difficult to tell if this is tongue-in-cheek humor or not. I sure hope it is because wow do I have some bad news for you if not...\n\n> Microsoft \"cheats\" on this as they define the use case AND they only report a specific level of vulnerability to the public.\n\nCorrect, that's another 20 year complaint from some of us on top of other issues MSRC has had on/off over the past. It's also something a vast majority of the industry don't realize until you point it out and they realize, \"oh wow, you are right... there are no 'low' advisories!\"\n\n> Sorry you feel we are a junk CNA, if you have specific issues with our being a CNA, please report them to us or to cve.org and we will be glad to address them.\n\nAgain? =) The primary complaint from so many of us has been shouted from the rooftops. The single biggest thing Kernel CNA could do to help the world is give us usable CVE descriptions that can be understood by non-kernel developers. Including just the commit message which is often extremely technical, has crash dumps, or whatever else just isn't helpful to most. When sharing vulnerability intelligence, it must be readable to a range of consumers from a CISO down to the security triage team.\n\n","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3886240439/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3886319620","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3886319620","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3886319620,"node_id":"IC_kwDOLyuXf87npIgE","user":{"login":"chandanbn","id":3230302,"node_id":"MDQ6VXNlcjMyMzAzMDI=","avatar_url":"https://avatars.githubusercontent.com/u/3230302?v=4","gravatar_id":"","url":"https://api.github.com/users/chandanbn","html_url":"https://github.com/chandanbn","followers_url":"https://api.github.com/users/chandanbn/followers","following_url":"https://api.github.com/users/chandanbn/following{/other_user}","gists_url":"https://api.github.com/users/chandanbn/gists{/gist_id}","starred_url":"https://api.github.com/users/chandanbn/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/chandanbn/subscriptions","organizations_url":"https://api.github.com/users/chandanbn/orgs","repos_url":"https://api.github.com/users/chandanbn/repos","events_url":"https://api.github.com/users/chandanbn/events{/privacy}","received_events_url":"https://api.github.com/users/chandanbn/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T18:58:04Z","updated_at":"2026-02-11T18:58:04Z","body":"Every general purpose product (open source or commercial) runs into the same dilemma: the exact same SQL database might be running a NASA mission, or tracking high scores on an arcade game machine.\n\nThat’s why CVSS tells the analyst to score a \"reasonable worst case.\" It’s not to factor every fringe or the most extreme scenario imaginable. Pick a plausible high-impact scenario and be consistent.\n\nIf NASA tried to calculate the gravitational pull of every butterfly wing before launching a rocket, nothing would ever leave the ground. Engineering and science work because we use approximations that are good enough to make decisions. Vulnerability scoring is the same: you generalize, make assumptions, state them, so you can prioritize and act, even when real-world deployments vary wildly.\n\nLets separate \"who\" from \"how\". While not perfect, CVSS 4 tell the \"how\" better than before. \n\nRe \"Who?\": When the supplier-ADP facility rolls out, the suppliers (at least the more important widely used ones like Android, Ubuntu, RedHat who re-package and support Linux) will be able to add their scores and perspectives. Neither Linux Kernel nor CISA have to provide a one-size-fits all score. Does that work @gregkh?","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3886319620/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887417808","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3887417808","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3887417808,"node_id":"IC_kwDOLyuXf87ntUnQ","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T21:51:41Z","updated_at":"2026-02-11T21:51:41Z","body":"To preface the answers below, right now there's no requirement to publish CVSS scores. The kernel's CVE team is not interested in doing that either. NVD and CISA definitely publish their own scores, but right now the scores published don't really reflect anything - not any particular usecase, nor some imaginary middle ground.\n\n@chandanbn I think you are correct that ADP is likely the right approach here. It allows users and vendors to score their particular use case, meaning we can eventually have multiple relevant CVSS scores for a single CVE rather than one generic score that fits nobody.\n\n@attritionorg regarding the descriptions, we simply do not have the expertise to improve them, nor can we force volunteers in an open source community to start writing CVE descriptions. If you or others are interested in improving the text of a CVE, we already have facilities to handle that, but to be clear, we can't do that work ourselves. There is simply no happy middle ground here regarding scoring because the use cases are so very different from each other that any attempt to do that will fail. A satellite use case is so different from a home entertainment system, and trying to come up with something in the middle will just make the score irrelevant to both.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887417808/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887608984","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3887608984","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3887608984,"node_id":"IC_kwDOLyuXf87nuDSY","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T22:36:15Z","updated_at":"2026-02-11T22:36:15Z","body":"Yes, ADP is the right approach here, and the work that cve.org is going forward with this seems like the correct solution.  We have no issue with external groups adding ADP to our CVE entries as it shows how they evaluate and rate the entry for their use case.\n\nAs long as there is no claim for \"this is the overall number score\" that can be issued to any specific entry, we will be happy.  What we have right now is not ok.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887608984/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887853974","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3887853974","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3887853974,"node_id":"IC_kwDOLyuXf87nu_GW","user":{"login":"amanion-cisa","id":168015703,"node_id":"U_kgDOCgO3Vw","avatar_url":"https://avatars.githubusercontent.com/u/168015703?v=4","gravatar_id":"","url":"https://api.github.com/users/amanion-cisa","html_url":"https://github.com/amanion-cisa","followers_url":"https://api.github.com/users/amanion-cisa/followers","following_url":"https://api.github.com/users/amanion-cisa/following{/other_user}","gists_url":"https://api.github.com/users/amanion-cisa/gists{/gist_id}","starred_url":"https://api.github.com/users/amanion-cisa/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/amanion-cisa/subscriptions","organizations_url":"https://api.github.com/users/amanion-cisa/orgs","repos_url":"https://api.github.com/users/amanion-cisa/repos","events_url":"https://api.github.com/users/amanion-cisa/events{/privacy}","received_events_url":"https://api.github.com/users/amanion-cisa/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-11T23:47:55Z","updated_at":"2026-02-11T23:47:55Z","body":"> Can you explain to me how the technical impact of a DoS vulnerability differs between a thermostat and a desktop computer?\n\nI usually frame CVSS (especially Base) as \"local technical severity.\" As others have noted in this thread, this does not account for application, context, environment, deployment, safety, integration, `#ifdef`, backporting, a hardware watchdog, etc. So absolutely, a kernel crash (or code execution!) in positive train control is a much different risk profile than in a thermostat. But CVSS Base doesn't account for this in the first place (yes CVSS has some non-Base ways to account for environment, especially in 4.0). So CVSS Base impact is C:N/I:N/A:H. If you throw in \"local, authenticated attacker and some weird edge configuration conditions\" I'd go with AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H (4.7). Adjust if the vulnerability is reachable over the network or if you think \"reasonable worst case\" is code execution.\n\nTLDR, CVSS Base doesn't really handle environment or context in the first place, so it's fairly straight forward to score a kernel vulnerability.\n\nAlso, this is not the answer about what Vulnrichment will or will not do, I'm just arguing generally that CVSS Base can be reasonably applied to Linux kernel vulnerabilities.","author_association":"COLLABORATOR","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3887853974/reactions","total_count":2,"+1":2,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3888153215","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3888153215","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3888153215,"node_id":"IC_kwDOLyuXf87nwIJ_","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-12T01:25:50Z","updated_at":"2026-02-12T01:25:50Z","body":"@amanion-cisa Take any netfilter vulnerability requiring CAP_NET_ADMIN. Is Privileges Required \"High\" or \"Low\"? If unprivileged user namespaces are enabled (Ubuntu default), any local user can unshare -U -n and obtain CAP_NET_ADMIN, so PR:L. If they're disabled (RHEL default), you need real privileges, so PR:H. Is this really an environmental adjustment or a fundamental disagreement about the base vector itself?\n\nWe can flip a coin and pick either PR:L or PR:H, but then the score becomes irrelevant to one of the parties and they have to go an start modifying it with Environmental.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3888153215/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893047951","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3893047951","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3893047951,"node_id":"IC_kwDOLyuXf87oCzKP","user":{"login":"zmanion","id":18131334,"node_id":"MDQ6VXNlcjE4MTMxMzM0","avatar_url":"https://avatars.githubusercontent.com/u/18131334?v=4","gravatar_id":"","url":"https://api.github.com/users/zmanion","html_url":"https://github.com/zmanion","followers_url":"https://api.github.com/users/zmanion/followers","following_url":"https://api.github.com/users/zmanion/following{/other_user}","gists_url":"https://api.github.com/users/zmanion/gists{/gist_id}","starred_url":"https://api.github.com/users/zmanion/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/zmanion/subscriptions","organizations_url":"https://api.github.com/users/zmanion/orgs","repos_url":"https://api.github.com/users/zmanion/repos","events_url":"https://api.github.com/users/zmanion/events{/privacy}","received_events_url":"https://api.github.com/users/zmanion/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-12T19:48:34Z","updated_at":"2026-02-12T19:57:28Z","body":"Hi @sashalevin, allow me to cotinue to play a strict interpreter of CVSS for this comment. A CVSS scorer at the kernel level, with knowledge of Ubuntu and Red Hat default configs, should follow \"worst reasonable case\" guidance and score PR:L. Red Hat could provide PR:H for their default configuration. The CVSS spec allows (encourages) higher fidelity downstream assessments, even without getting into the Environmental vectors (or, in CVSS 4.0, Modified Base Vectors).\n\nTLDR, people should re-assess CVSS (and other risk information) for their context and not rely solely on aybody's upstream CVSS Base vectors. The upstream Base (if it exists) is only a starting point, accept it unmodified (edit: or without additional context) at your own peril.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893047951/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893259774","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3893259774","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3893259774,"node_id":"IC_kwDOLyuXf87oDm3-","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-12T20:35:34Z","updated_at":"2026-02-12T20:35:34Z","body":"@zmanion and I'd argue that for almost any kernel CVE I can find a plausible \"worst reasonable case\" that will score that CVE as critical :)\n\nLet's pick a random \"medium\" scored CVE: CVE-2025-38177.\n\n1. The UAF gives a dangling rbtree pointer to freed kernel heap memory, so really it's an arbitrary read/write into kernel memory. \"C:N/I:N\" turn to \"C:H/I:H\" (5.5 -> 7.8)\n2. In any container deployment, the netlink interface is reachable from within a pod's network namespace, and kernel code execution escapes all container isolation, compromising the host and co-tenant workloads. \"S:U\" turns to \"S:C\" (7.8 -> 8.8).\n3. In a cloud environment the attacker never has local access to the host, so the attack would be via the network, not a local one. \"AV:L\" turns to \"AV:A\" (8.8 -> 9.0).\n\nAnd this is all before digging into the weird (but reasonable - used in practice) usecases we've seen for the kernel.\n\nSo honestly, if CISA wants to really look at the worst reasonable case which will effectively result in a 9.0+ score for most CVEs, I won't object.\n","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893259774/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893433284","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3893433284","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3893433284,"node_id":"IC_kwDOLyuXf87oERPE","user":{"login":"003random","id":22357749,"node_id":"MDQ6VXNlcjIyMzU3NzQ5","avatar_url":"https://avatars.githubusercontent.com/u/22357749?v=4","gravatar_id":"","url":"https://api.github.com/users/003random","html_url":"https://github.com/003random","followers_url":"https://api.github.com/users/003random/followers","following_url":"https://api.github.com/users/003random/following{/other_user}","gists_url":"https://api.github.com/users/003random/gists{/gist_id}","starred_url":"https://api.github.com/users/003random/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/003random/subscriptions","organizations_url":"https://api.github.com/users/003random/orgs","repos_url":"https://api.github.com/users/003random/repos","events_url":"https://api.github.com/users/003random/events{/privacy}","received_events_url":"https://api.github.com/users/003random/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-12T21:17:19Z","updated_at":"2026-02-12T21:17:19Z","body":"@sashalevin, \n\nCVSS wants you to assume `reasonable worst case`. With the emphasis on `reasonable`. I very much agree that this is the most subjective part of the specification, and I personally dislike it too. That said, we could expect all memory issues to become code execution (unfortunately, NIST seems to do that), but reasonably, most are just integrity or availability issues unless proven otherwise.\n\nAdditionally, about your point on cloud environments. The vulnerability would still require local access, even if the attacker is remote (e.g. cloud env, or via SSH). CVSS sees this as local, regardless.\n\nSupporting material:\n1. https://www.first.org/cvss/v3.1/specification-document#:~:text=or%20remotely%20(e.g.%2C%20SSH)\n2. https://www.first.org/cvss/v3-1/mastering-cvss-3-1-transcript#:~:text=For%20another%20example%2C%20if%20shell%20access%20on%20a%20system%20is%20required%20to%20exploit%20a%20system%20vulnerability%20and%20SSH%20is%20simply%20the%20method%20for%20obtaining%20the%20shell%2C%20then%20Attack%20Vector%20is%20Local.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893433284/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893559105","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3893559105","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3893559105,"node_id":"IC_kwDOLyuXf87oEv9B","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-12T21:45:14Z","updated_at":"2026-02-12T21:45:14Z","body":"@003random On AV:L: consider a malicious container image pushed to a registry. The orchestrator pulls and runs it autonomously. The attacker never authenticates to or interacts with the host. That's structurally identical to a malicious document processed server-side, which CVSS scores AV:N. If the counterargument is that the exploit runs as local syscalls, then every RCE payload would be AV:L once it executes.\n\nBy the time this GitHub issue closes I could probably be a licensed lawyer :)","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3893559105/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3898425404","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3898425404","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3898425404,"node_id":"IC_kwDOLyuXf87oXUA8","user":{"login":"amanion-cisa","id":168015703,"node_id":"U_kgDOCgO3Vw","avatar_url":"https://avatars.githubusercontent.com/u/168015703?v=4","gravatar_id":"","url":"https://api.github.com/users/amanion-cisa","html_url":"https://github.com/amanion-cisa","followers_url":"https://api.github.com/users/amanion-cisa/followers","following_url":"https://api.github.com/users/amanion-cisa/following{/other_user}","gists_url":"https://api.github.com/users/amanion-cisa/gists{/gist_id}","starred_url":"https://api.github.com/users/amanion-cisa/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/amanion-cisa/subscriptions","organizations_url":"https://api.github.com/users/amanion-cisa/orgs","repos_url":"https://api.github.com/users/amanion-cisa/repos","events_url":"https://api.github.com/users/amanion-cisa/events{/privacy}","received_events_url":"https://api.github.com/users/amanion-cisa/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-13T17:32:26Z","updated_at":"2026-02-13T17:33:03Z","body":"(If it isn't obvious, @zmanion and @amanion-cisa are the same human, me, sorry for the accidental identity crisis.)\n\n@sashalevin:\n\n> consider a malicious container image pushed to a registry. The orchestrator pulls and runs it autonomously. The attacker never authenticates to or interacts with the host. That's structurally identical to a malicious document processed server-side, which CVSS scores AV:N. If the counterargument is that the exploit runs as local syscalls, then every RCE payload would be AV:L once it executes.\n\nThe \"download and execute malicous code (container)\" aspect of this I would not treat as a vulnerability (no CVE, no CVSS). I know that historically CVE IDs have been assigned to things like the compromise of XZ Utils source CVE-2024-3094, but those assignments are wrong). If the downloaded malicous code (container) then exploits a vulnerability, that's where CVSS comes into play.\n\nIn CVSS terms, a one-click browser vulnerability is AV:N (\"...[bound to the network stack](https://www.first.org/cvss/v3.1/user-guide#3-3-Local-Vulnerabilities-Exploited-by-Remote-Attackers)\"), downloading and opening a file is AV:L. And as nearly always, there is context, my default configuration may be to automatically download and open a file.\n\nEdit: Sadly I don't think there's a big market for CVSS lawyers.","author_association":"COLLABORATOR","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3898425404/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3900518924","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-3900518924","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":3900518924,"node_id":"IC_kwDOLyuXf87ofTIM","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-02-14T02:46:10Z","updated_at":"2026-02-14T02:46:10Z","body":"@amanion-cisa You're probably right - I really don't know all the nitty gritty details here.\n\nHowever, the current scoring situation highlights exactly why the system is broken. Currently, almost everything defaults to a 5.5. Do you know how many kernel CVEs scored higher than 8.0 in 2025? A whooping 2.\n\nThis suggests that without the context provided by ADPs, the scoring creates a \"false middle\" that doesn't represent the risk for anyone. It's too low for enterprise servers and potentially irrelevant for embedded devices. This is why we need downstream vendors to provide the real scores, rather than relying on a generic upstream number that ends up being meaningless.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/3900518924/reactions","total_count":2,"+1":2,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4012511627","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-4012511627","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":4012511627,"node_id":"IC_kwDOLyuXf87vKhGL","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-03-06T15:46:58Z","updated_at":"2026-03-06T15:46:58Z","body":"Any word on this request?","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4012511627/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4095148435","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-4095148435","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":4095148435,"node_id":"IC_kwDOLyuXf870FwGT","user":{"login":"todb","id":24144,"node_id":"MDQ6VXNlcjI0MTQ0","avatar_url":"https://avatars.githubusercontent.com/u/24144?v=4","gravatar_id":"","url":"https://api.github.com/users/todb","html_url":"https://github.com/todb","followers_url":"https://api.github.com/users/todb/followers","following_url":"https://api.github.com/users/todb/following{/other_user}","gists_url":"https://api.github.com/users/todb/gists{/gist_id}","starred_url":"https://api.github.com/users/todb/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/todb/subscriptions","organizations_url":"https://api.github.com/users/todb/orgs","repos_url":"https://api.github.com/users/todb/repos","events_url":"https://api.github.com/users/todb/events{/privacy}","received_events_url":"https://api.github.com/users/todb/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-03-20T03:12:07Z","updated_at":"2026-03-20T03:12:07Z","body":"Fwiw, I think Kernel.org is an exemplary CNA. Loads of CVEs issued against real security issues regardless of severity, clear descriptions for their intended audience, and links to diffs if you want to learn more.\n\nFuture bug archeologists will appreciate these CVEs.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4095148435/reactions","total_count":6,"+1":3,"-1":0,"laugh":2,"hooray":1,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4099453720","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-4099453720","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":4099453720,"node_id":"IC_kwDOLyuXf870WLMY","user":{"login":"attritionorg","id":3095424,"node_id":"MDQ6VXNlcjMwOTU0MjQ=","avatar_url":"https://avatars.githubusercontent.com/u/3095424?v=4","gravatar_id":"","url":"https://api.github.com/users/attritionorg","html_url":"https://github.com/attritionorg","followers_url":"https://api.github.com/users/attritionorg/followers","following_url":"https://api.github.com/users/attritionorg/following{/other_user}","gists_url":"https://api.github.com/users/attritionorg/gists{/gist_id}","starred_url":"https://api.github.com/users/attritionorg/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/attritionorg/subscriptions","organizations_url":"https://api.github.com/users/attritionorg/orgs","repos_url":"https://api.github.com/users/attritionorg/repos","events_url":"https://api.github.com/users/attritionorg/events{/privacy}","received_events_url":"https://api.github.com/users/attritionorg/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-03-20T16:36:34Z","updated_at":"2026-03-20T16:36:34Z","body":"@todb Disagree on \"clear descriptions for their intended audience\"\n\nhttps://docs.kernel.org/process/cve.html\n\"Only those individuals with **deep expertise and intimate knowledge** of the subsystem can effectively assess the validity and scope of a reported vulnerability and determine its appropriate CVE designation.\"\n\nWhen only developers of the subsystem can accurately determine if a vulnerability, then CVE descriptions with convoluted descriptions, KSAN / ASAN output, etc. are not helpful to the \"intended audience\" which are CVE stakeholders. That means everyone using CVE, not just kernel developers with said \"deep expertise and intimate knowledge\".\n\nPer Kernel's description, CISA, NVD, and any VDB is not suited to provide CVSS scores, and the Kernel CNA refuses to.\n\nSincerely,\na vulnerability historian / archeologist / anthropologist","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4099453720/reactions","total_count":1,"+1":1,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4150189862","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-4150189862","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":4150189862,"node_id":"IC_kwDOLyuXf873Xt8m","user":{"login":"gregkh","id":14953,"node_id":"MDQ6VXNlcjE0OTUz","avatar_url":"https://avatars.githubusercontent.com/u/14953?v=4","gravatar_id":"","url":"https://api.github.com/users/gregkh","html_url":"https://github.com/gregkh","followers_url":"https://api.github.com/users/gregkh/followers","following_url":"https://api.github.com/users/gregkh/following{/other_user}","gists_url":"https://api.github.com/users/gregkh/gists{/gist_id}","starred_url":"https://api.github.com/users/gregkh/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/gregkh/subscriptions","organizations_url":"https://api.github.com/users/gregkh/orgs","repos_url":"https://api.github.com/users/gregkh/repos","events_url":"https://api.github.com/users/gregkh/events{/privacy}","received_events_url":"https://api.github.com/users/gregkh/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-03-29T13:43:33Z","updated_at":"2026-03-29T13:43:33Z","body":"We will have to set a deadline here, sorry.  If we don't get a response by the end of this month (i.e. March 31, 2026), the Linux CNA will start adding our own interpretation of CVSS scores to our CVE records, as we are allowed to.  It _might_ contain a bit higher number than you expect, so we really do not want to do this, but given that your \"enrichment\" is causing users and vendors to avoid applying applicable CVE fixes to their systems, we have no other choice in order to ensure that Linux users remain secure.\n\n","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4150189862/reactions","total_count":4,"+1":2,"-1":0,"laugh":0,"hooray":1,"confused":0,"heart":0,"rocket":1,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4254451821","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-4254451821","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":4254451821,"node_id":"IC_kwDOLyuXf879lcht","user":{"login":"attritionorg","id":3095424,"node_id":"MDQ6VXNlcjMwOTU0MjQ=","avatar_url":"https://avatars.githubusercontent.com/u/3095424?v=4","gravatar_id":"","url":"https://api.github.com/users/attritionorg","html_url":"https://github.com/attritionorg","followers_url":"https://api.github.com/users/attritionorg/followers","following_url":"https://api.github.com/users/attritionorg/following{/other_user}","gists_url":"https://api.github.com/users/attritionorg/gists{/gist_id}","starred_url":"https://api.github.com/users/attritionorg/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/attritionorg/subscriptions","organizations_url":"https://api.github.com/users/attritionorg/orgs","repos_url":"https://api.github.com/users/attritionorg/repos","events_url":"https://api.github.com/users/attritionorg/events{/privacy}","received_events_url":"https://api.github.com/users/attritionorg/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-04-15T18:23:22Z","updated_at":"2026-04-15T18:23:30Z","body":"[popcorn emoji]","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/4254451821/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5147304510","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5147304510","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5147304510,"node_id":"IC_kwDOLyuXf88AAAABMs2iPg","user":{"login":"amanion-cisa","id":168015703,"node_id":"U_kgDOCgO3Vw","avatar_url":"https://avatars.githubusercontent.com/u/168015703?v=4","gravatar_id":"","url":"https://api.github.com/users/amanion-cisa","html_url":"https://github.com/amanion-cisa","followers_url":"https://api.github.com/users/amanion-cisa/followers","following_url":"https://api.github.com/users/amanion-cisa/following{/other_user}","gists_url":"https://api.github.com/users/amanion-cisa/gists{/gist_id}","starred_url":"https://api.github.com/users/amanion-cisa/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/amanion-cisa/subscriptions","organizations_url":"https://api.github.com/users/amanion-cisa/orgs","repos_url":"https://api.github.com/users/amanion-cisa/repos","events_url":"https://api.github.com/users/amanion-cisa/events{/privacy}","received_events_url":"https://api.github.com/users/amanion-cisa/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-07-31T20:45:13Z","updated_at":"2026-07-31T20:45:13Z","body":"> \"enrichment\" is causing users and vendors to avoid applying applicable CVE fixes to their systems\n\nAnyone prioritizing or assessing risk based solely on CVSS Base scores (from anyone, CNA, Vulnrichment, NVD) is doing it utterly wrong. I appreciate that CVSS supports Temporal and Enviornmental metrics, I observe little use of them, and I claim that they don't help much. Properties (often subjective or local) of the things that are vulnerable might be more important than CVSS properties. This thread has already covered this: (Linux in a consumer thermostat) has different properties than (Linux in a positive train control sytem).\n\nIf a Linux kernel vulnerability reasonably worst case is remotely exploitable, unauthenticated, and could execute arbitrary code, well, that is technically severe, 9.8. If I somehow don't run or depend on a Linux kernel somewhere, my subjective risk is zero. That doesn't mean hacking the CVSS assessment, it means applying addtional context, beyond CVSS.","author_association":"COLLABORATOR","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5147304510/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5147340341","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5147340341","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5147340341,"node_id":"IC_kwDOLyuXf88AAAABMs4uNQ","user":{"login":"amanion-cisa","id":168015703,"node_id":"U_kgDOCgO3Vw","avatar_url":"https://avatars.githubusercontent.com/u/168015703?v=4","gravatar_id":"","url":"https://api.github.com/users/amanion-cisa","html_url":"https://github.com/amanion-cisa","followers_url":"https://api.github.com/users/amanion-cisa/followers","following_url":"https://api.github.com/users/amanion-cisa/following{/other_user}","gists_url":"https://api.github.com/users/amanion-cisa/gists{/gist_id}","starred_url":"https://api.github.com/users/amanion-cisa/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/amanion-cisa/subscriptions","organizations_url":"https://api.github.com/users/amanion-cisa/orgs","repos_url":"https://api.github.com/users/amanion-cisa/repos","events_url":"https://api.github.com/users/amanion-cisa/events{/privacy}","received_events_url":"https://api.github.com/users/amanion-cisa/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-07-31T20:50:01Z","updated_at":"2026-07-31T20:50:01Z","body":"Sorry what I really came here to say and ask is this: We've seen some (1208 out of 3375 since the start of 2026) Linux kernel CNA Records with CVSS information. Standard Vulnrichment policy, which has not changed, is to accept CNA-provided CVSS information. I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion, and Vulnrichment may start assessing CVSS again (for Records missing a CNA-provided CVSS assessment).\n\nIs there some criteria the kernel CNA uses to decide when to assess CVSS?","author_association":"COLLABORATOR","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5147340341/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5152265900","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5152265900","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5152265900,"node_id":"IC_kwDOLyuXf88AAAABMxlWrA","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-08-01T16:15:12Z","updated_at":"2026-08-01T16:15:12Z","body":"> If a Linux kernel vulnerability reasonably worst case is remotely exploitable, unauthenticated, and could execute arbitrary code, well, that is technically severe, 9.8.\n\nThat's our method. We score against the worst reasonable use case we can come up with for the bug. We don't average across deployments or try to model a typical Linux box.\n\n> We've seen some (1208 out of 3375 since the start of 2026) Linux kernel CNA Records with CVSS information.\n\nRight. We've started scoring as a response to the silence in this issue.\n\n> I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion\n\nWe weren't told. We found out from your comment.\n\n> Is there some criteria the kernel CNA uses to decide when to assess CVSS?\n\nWorst reasonable use case.\n\nThe work is in `git://git.kernel.org/pub/scm/linux/security/vulns.git`. Example:\n\nhttps://git.kernel.org/pub/scm/linux/security/vulns.git/commit/?id=d87a2f1e8733ca60e3adea7db210c0dd3024f6f9\n\nThat reasoning lives in the commit message.\n\nIf you think a score is wrong, mail cve@kernel.org with the metric and the argument. We'll fix it or explain it.\n\nSo the ask, if Vulnrichment resumes on kernel records: publish the reasoning, not just the vector. A score someone can argue with is useful even when it's wrong. A bare number isn't.\n\nCWE is still being added, by the way. CVE-2026-53264 and CVE-2026-53359 both got CWE-416 on 2026-07-29. Separate conversation.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5152265900/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5160764181","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5160764181","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5160764181,"node_id":"IC_kwDOLyuXf88AAAABM5sDFQ","user":{"login":"zmanion","id":18131334,"node_id":"MDQ6VXNlcjE4MTMxMzM0","avatar_url":"https://avatars.githubusercontent.com/u/18131334?v=4","gravatar_id":"","url":"https://api.github.com/users/zmanion","html_url":"https://github.com/zmanion","followers_url":"https://api.github.com/users/zmanion/followers","following_url":"https://api.github.com/users/zmanion/following{/other_user}","gists_url":"https://api.github.com/users/zmanion/gists{/gist_id}","starred_url":"https://api.github.com/users/zmanion/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/zmanion/subscriptions","organizations_url":"https://api.github.com/users/zmanion/orgs","repos_url":"https://api.github.com/users/zmanion/repos","events_url":"https://api.github.com/users/zmanion/events{/privacy}","received_events_url":"https://api.github.com/users/zmanion/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-08-02T23:02:08Z","updated_at":"2026-08-02T23:02:08Z","body":">> I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion\n>\n> We weren't told. We found out from your comment.\n\nI should or could have know this earlier and said something, and will try to finally resolve this issue (at least time around). I believe (but will need to confirm) that standard Vulnrichment policy will continue wrt the Linux kernel CNA: add CVSS and CWE if the CNA has not.\n\n> Worst reasonable use case.\n> ...\n> That reasoning lives in the commit message.\n> ...\n> So the ask, if Vulnrichment resumes on kernel records: publish the reasoning, not just the vector. A score someone can argue with is useful even when it's wrong.\n\nI understand worst reasonable case (at least as defined by CVSS), and appreciate the reasoning for the vectors. Maybe Vulnrichment can be updated to support such reasoning, even if this might involve some hacking of the CVE and CVSS schemas.\n\nBut what I was really asking is how the kernel CNA decides to add CVSS or not. For example, [CVE-2026-64536](https://cveawg.mitre.org/api/cve/CVE-2026-64536) is scored while [CVE-2026-64537](https://cveawg.mitre.org/api/cve/CVE-2026-64537) is not. I'm curious in one sense if you have some sort of \"score CVSS or not\" test, but also to get an idea of what proportion of Records you'll be scoring.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5160764181/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5165528611","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5165528611","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5165528611,"node_id":"IC_kwDOLyuXf88AAAABM-O2Iw","user":{"login":"sashalevin","id":860392,"node_id":"MDQ6VXNlcjg2MDM5Mg==","avatar_url":"https://avatars.githubusercontent.com/u/860392?v=4","gravatar_id":"","url":"https://api.github.com/users/sashalevin","html_url":"https://github.com/sashalevin","followers_url":"https://api.github.com/users/sashalevin/followers","following_url":"https://api.github.com/users/sashalevin/following{/other_user}","gists_url":"https://api.github.com/users/sashalevin/gists{/gist_id}","starred_url":"https://api.github.com/users/sashalevin/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/sashalevin/subscriptions","organizations_url":"https://api.github.com/users/sashalevin/orgs","repos_url":"https://api.github.com/users/sashalevin/repos","events_url":"https://api.github.com/users/sashalevin/events{/privacy}","received_events_url":"https://api.github.com/users/sashalevin/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-08-03T11:05:52Z","updated_at":"2026-08-03T11:05:52Z","body":"> I should or could have know this earlier and said something, and will try to finally resolve this issue (at least time around).\n\nThanks.\n\n> I believe (but will need to confirm) that standard Vulnrichment policy will continue wrt the Linux kernel CNA: add CVSS and CWE if the CNA has not.\n\nThat's the part I'd push back on, see below.\n\n> Maybe Vulnrichment can be updated to support such reasoning, even if this might involve some hacking of the CVE and CVSS schemas.\n\nIt doesn't have to go in the record, just somewhere accessible where both the public and the CNA are able to understand the reasoning behind the assignments. \n\nIf you do want it in the record, maybe something like `metrics[].scenarios[].value`? Should we be using that too?\n\n> But what I was really asking is how the kernel CNA decides to add CVSS or not. For example, CVE-2026-64536 is scored while CVE-2026-64537 is not.\n\nSorry, I answered the wrong half of that. There's no \"score or not\" test. We don't have the resources to score everything, so we score what we think matters more.\n\nYour two examples are roughly that judgement.\n\n> but also to get an idea of what proportion of Records you'll be scoring.\n\nI think that what you see for 2026 (~40%) are about the numbers we expect going forward. We're looking to backfill eariler years too.","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5165528611/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null},{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5957975315","html_url":"https://github.com/cisagov/vulnrichment/issues/262#issuecomment-5957975315","issue_url":"https://api.github.com/repos/cisagov/vulnrichment/issues/262","id":5957975315,"node_id":"IC_kwDOLyuXf88AAAABYx99Ew","user":{"login":"MarkovianProtocol","id":292588966,"node_id":"U_kgDOEXCNpg","avatar_url":"https://avatars.githubusercontent.com/u/292588966?v=4","gravatar_id":"","url":"https://api.github.com/users/MarkovianProtocol","html_url":"https://github.com/MarkovianProtocol","followers_url":"https://api.github.com/users/MarkovianProtocol/followers","following_url":"https://api.github.com/users/MarkovianProtocol/following{/other_user}","gists_url":"https://api.github.com/users/MarkovianProtocol/gists{/gist_id}","starred_url":"https://api.github.com/users/MarkovianProtocol/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/MarkovianProtocol/subscriptions","organizations_url":"https://api.github.com/users/MarkovianProtocol/orgs","repos_url":"https://api.github.com/users/MarkovianProtocol/repos","events_url":"https://api.github.com/users/MarkovianProtocol/events{/privacy}","received_events_url":"https://api.github.com/users/MarkovianProtocol/received_events","type":"User","user_view_type":"public","site_admin":false},"created_at":"2026-10-02T17:42:55Z","updated_at":"2026-10-02T17:42:55Z","body":"We measured SSVC coverage on CVE records this week. All 1,731 KEV CVEs and every non-kernel CVE in a random sample since 10 June carry CISA-ADP's three SSVC decision points. Of Linux kernel CNA records, 0 of 53 sampled since 10 June and 1 of 158 since March do. Is the CVSS pause described above also holding back SSVC for kernel records? Data and scripts: https://markovianprotocol.com/measurements/sm-008.html\n","author_association":"NONE","pin":null,"reactions":{"url":"https://api.github.com/repos/cisagov/vulnrichment/issues/comments/5957975315/reactions","total_count":0,"+1":0,"-1":0,"laugh":0,"hooray":0,"confused":0,"heart":0,"rocket":0,"eyes":0},"performed_via_github_app":null,"minimized":null}]