[Cryptography] This is it, we're all going to die

Theodore Ts'o tytso at mit.edu
Thu Dec 30 12:12:23 EST 2021

On Mon, Dec 27, 2021 at 06:05:26AM +0000, Peter Gutmann wrote:
> While searching for something vaguely related, Google turned up this:
>   https://www.spinics.net/lists/stable-commits/msg184308.html
>   Patch "X.509: Fix crash caused by NULL pointer" has been added to the 5.10-stable tree
> The Linux kernel has X.509 processing inside it.
> We're all going to die.

It could be worse.  Your CPU could have a hidden x.509 processing code
*and* a web server, that isn't getting regular security patches, and
was probably written by firmware engieners.

Oh, wait....


Happy new year!

						- Ted

More information about the cryptography mailing list