A team from the University of Minnesota explained the motives behind experiments with questionable commits to the Linux kernel.

A group of researchers from the University of Minnesota, whose changes were recently blocked by Greg Kroah-Hartman, published an open letter apologizing and explaining the motives behind their actions. Recall that the group was investigating vulnerabilities in the review process of incoming patches and assessing the possibility of advancing changes with hidden flaws into the kernel. After receiving a questionable patch with a meaningless fix from one of the group members, it was assumed that the researchers were once again attempting to experiment on kernel developers. Since such experiments potentially pose a security threat and waste committers' time, it was decided to block the acceptance of changes and send all previously accepted patches for re-review.

In their open letter, the group members stated that their activities were motivated solely by good intentions and a desire to improve the change review process by identifying and eliminating vulnerabilities. The group has been studying processes that lead to vulnerabilities for many years and actively works to discover and eliminate vulnerabilities in the Linux kernel. It is claimed that all 190 patches sent for re-review are legitimate, fix existing issues, and do not contain intentional errors or hidden vulnerabilities.

The concerning research on advancing hidden vulnerabilities was conducted last August and was limited to sending three erroneous patches, none of which made it into the kernel codebase. The activity related to these patches was limited to discussion, and the advancement of the patches was halted before the changes could be added to Git. The code for the three problematic patches is currently not provided, as revealing it would disclose the identities of those who conducted the initial review (the information will be disclosed after obtaining consent from the developers who did not recognize the errors).

The primary source of the research was not the patches themselves, but an analysis of previously added patches to the kernel that subsequently revealed vulnerabilities. The University of Minnesota team had no involvement in the addition of these patches. A total of 138 problematic patches that caused errors were studied, and by the time the research results were published, all related errors had been fixed, including with the participation of the team conducting the research.

The researchers regret that they used an inappropriate method for conducting the experiment. The mistake was that the research was conducted without obtaining permission and without notifying the community. The motive behind the covert activity was the desire to ensure the purity of the experiment, as notification could draw particular attention to the patches and their evaluation on a non-general basis. Despite the intention to improve kernel security, the researchers have now realized that using the community as a guinea pig was incorrect and unethical. They assure that they would never intentionally harm the community or allow new vulnerabilities to be introduced into the kernel's working code.

Regarding the meaningless patch that served as the catalyst for the blocking, it is not related to the past research and is associated with a new project aimed at creating a toolkit for automated detection of errors that arise from the addition of other patches.

The group members are now trying to find ways to return to participating in development and are intent on repairing their relationships with the Linux Foundation and the developer community, proving their usefulness in enhancing kernel security and expressing a desire to work diligently for the common good and restore trust.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster