Open Source Market Segment LS
Open Source Market Segment RS
Sunday, 19 May 2024 18:34

Kernels shipped by Linux vendors 'less secure than upstream stable offering' Featured

By
Kernels shipped by Linux vendors 'less secure than upstream stable offering' Image by OpenClipart-Vectors from Pixabay

Three software engineers from CIQ, a Linux company, have found that the kernels shipped by commercial firms have more unpatched flaws than the upstream stable kernel which is maintained by Linux developer Greg Kroah-Hartman.

In a statement issued on Wednesday, Jeremy Allison, Ronnie Sahlberg and Jonathan Maple said on the surface it would appear that "carefully curated software patches applied to a known Linux kernel, frozen at a specific release, would obviously seem to be preferable to the random walk of an upstream open source Linux project".

However, after a great deal of data analysis, the trio came to the inescapable conclusion that kernels that came with a commercial distribution were not preferable.

"The data shows that 'frozen' vendor Linux kernels, created by branching off a release point and then using a team of engineers to select specific patches to back-port to that branch, are buggier than the upstream “stable” Linux kernel created by Kroah-Hartman," they said.

Allison, Sahlberg and Maple have written a detailed white paper outlining their reasoning for this conclusion. CIQ produces an enterprise Linux distribution known as Rocky Linus which claims to be a drop-in replacement for CentOS, an enterprise distribution that was bought by Red Hat in 2014 and then shut down.

In June 2023, Red Hat, which is owned by IBM which bought it in 2019, tightened its grip on RHEL source code, and said it would make source code available only to its paying customers.

Rocky Linux has presented itself as an alternative to CentOS, something that takes on added significance given that CentOS 7, the last version that was put out before Red Hat's restrictions made it impossible to have a new version, reaching its end-of-life on 30 June.

CIQ is offering something called CIQ Bridge "with up to three years of additional life for CentOS 7 beyond the official EOL, covering critical security updates for CVSS scores of 7 and above".

Allison, Sahlberg and Maple said they had reached the following conclusions from their research:

  • A 'frozen' vendor kernel is an insecure kernel. A vendor kernel released later in the release schedule is doubly so.
  • The number of known bugs in a 'frozen' vendor kernel grows over time.
  • The growth in the number of bugs even accelerates over time.
  • There are too many open bugs in these kernels for it to be feasible to analyse or even classify them.

"There are still reasons you might still select a 'frozen' vendor kernel," the trio said. "One of them [is that] a vendor-defined internal kernel application binary interface doesn’t change over the lifetime of the release.

"If you are using hardware where the device driver hasn’t (or won’t, due to the attitude of the manufacturer) been submitted to the upstream Linux code tree then you may have no choice, but to use a vendor kernel.

"Having said that, the Linux kernel used by Android devices is based on the upstream kernel and also has a stable internal kernel ABI, so this isn’t an insurmountable problem.

"But thinking that you’re making a more secure choice by using a 'frozen' vendor kernel isn’t a luxury we can still afford to believe."

Read 1636 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




IDC WHITE PAPER: The Business Value of Aiven Data Cloud Solutions

According to IDC, Aiven enables your teams to perform more efficiently, reduce direct infrastructure costs, and provide improved database performance, agility and scalability.

Find out how Aiven makes teams 48% more efficient, allowing staff to focus on high-value activities that drive real business results:

340% 3-year ROI – break even in 5 months (average)

37% lower 3-year cost of operations

78% reduction in staff time for database deployments


Download the IDC White Paper now

DOWNLOAD WHITE PAPER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Sam Varghese

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.

Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown:

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments