On Thu, Jul 23, 2026 at 11:35:54AM +0100, Kevin Chadwick wrote:
> 
> 
> -------- Original Message --------
> 
> > Usually, audits allow for notifying as a false positive as scanning tools 
> > often
> > have false positives or technical vulnerabilities that aren't exploitable.
> > 
> > It sounds like these are all false positives unless your servers ssh client 
> > is
> > connecting to some oddly managed server.
> 
> To further the point. Debian stables security team routinely marks packages as
> unaffected by a CVE or other language along the lines of rare or very unlikely
> to be an issue whilst updating the package in unstable. You could ask them 
> about
> Debian stable servers as surely they would have not required unstable to be 
> used.
> 
> -- 
> All the best,
>              Kevin Chadwick

I would not be surprised if there is some Enterprise Linux Distro that
fulfills this "need", and equally not surprised if there is a business
relation between that and the Black Kite security scanning tool...

Cheers!
-- 

/ Raimo Niskanen, Erlang/OTP, Ericsson AB

Reply via email to