Hacker News new | past | comments | ask | show | jobs | submit
As the person who wrote the fix for this issue (and not the original code), I will just mention that I find this paragraph makes the author sound incredibly entitled:

    Shamefully, the inetutils project hasn’t actually released a fixed version of their software (at least at the time of publishing).
The bug was reported on a public mailing list, which is sadly common nowadays [1]. After my workday, during which I was not able to review the report, I wrote a script to confirm the bug was real, since I was seeing way too many slop reports at the time. Then I sent a patch before going to bed [2]. A third party then graciously shared the patch on oss-security [3], which all distributions follow. There is no need to make a new release, which is harder for the distributions than simply applying a small patch.

Perhaps I am just unlucky in my interactions, but I feel like this entitlement is too common among software security people. Note that I see zero return in spending time working on Inetutils, and I find other projects I work on more interesting.

[1] https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [2] https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [3] https://www.openwall.com/lists/oss-security/2026/03/12/4

The not-so-silent minority hanging out on HN know that the true heroes are those who take the time and put in the effort, and then put even more effort to reply and post about it here.

Thanks to all of our heroes, op included.

> The not-so-silent minority hanging out on HN know that the true heroes are those who take the time and put in the effort, and then put even more effort to reply and post about it here.

We know that the entirety of the AI movement is built on top of open-source projects like Linux and all the terminal and command line utilities. And runs inside projects doing god's work (say to contain the agents) like QEMU etc.

AI lives inside the work of our open-source heroes and would be absolutely nowhere without the work of all those people.

> Thanks to all of our heroes, op included.

Definitely, thanks GP and thanks to all our heroes.

loading story #49738146
loading story #49736638
loading story #49737449
loading story #49737584
loading story #49736577
loading story #49737337
loading story #49736733
> In fact, this vulnerability was born so long ago (way back in 1994)

> That was so long ago that RISC was still a distant dream.

Yeah ARM would like to have a word with you. I'd been using RISC on the desktop for about five years by then and I was not an early adopter.

loading story #49736956
loading story #49736884
loading story #49736914
loading story #49736537
loading story #49736140
RISC was not a distant dream in 1994 LMAO.
loading story #49737921
loading story #49737345