Sudo Show
Sudo Show
Sudo Show
76: ABCs of CVEs | SUDO Show 76
51 minutes Posted May 14, 2026 at 11:00 am.
Intro – ABCs of CVEs
Conferences and the Framework 13 Pro
What Has Brandon Been Up To?
AI and CVEs – Claude and Friends
Pack2TheRoot – PackageKit and Fedora Workstation
copy.fail – Kernel Optimization Gone Wrong
Dirty Frag – Embargo, Break, and Rapid Response
How CVEs Are Reported and Coordinated
Brandon’s CVE Patching Best Practices
Testing and Releasing Patches Safely
Communications, CVSS Scores, and Risk
Tools – Foreman, Uyuni, and CVE Lists
Tools to Figure Out Which CVEs Matter
Yes, I Use AI Every Day
Counterpoint on AI
Quantifying and Prioritizing Risk
Does Immutability Save You?
Zero CVE – Is It Possible?
0:00
51:43
Download MP3
Show notes

SUDO Show 76, “ABCs of CVEs,” breaks down how modern Linux vulnerabilities go from scary headlines to real-world fixes. Bill, Neal, and Brandon start with conferences and Neal’s new Framework 13 Pro running Fedora, then dive into AI‑assisted security research and what tools like Claude and others are actually doing in the CVE pipeline. Neal walks through recent high‑profile issues like Pack2TheRoot in PackageKit, the copy.fail kernel optimization bug, and the Dirty Frag vulnerability, explaining how disclosure, embargoes, and coordination really work from a distro maintainer’s perspective. Brandon then focuses on CVE patching best practices, testing and release strategies, tools like Foreman and Uyuni for managing updates, and how to interpret CVSS scores and risk without panicking, before the crew wraps with advice for new grads who want to get into security without setting their hair—or their clusters—on fire.

Show Links:

Connect with the Hosts:

Bill - @ctlinux on Mastodon
Neal - @[email protected] on Mastodon
Noel - https://github.com/noelmiller