Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Linux OS vulnerabilities (CVEs) #26804

Open
allenhouchins opened this issue Mar 4, 2025 · 2 comments
Open

Linux OS vulnerabilities (CVEs) #26804

allenhouchins opened this issue Mar 4, 2025 · 2 comments
Labels
~dogfood Issue resulted from Fleet's product dogfooding. prospect-universitas

Comments

@allenhouchins
Copy link
Member

allenhouchins commented Mar 4, 2025

  • @noahtalerman: User requested this because Fleet already maps CVE and vulnerability data for Linux hosts, but the Software > OS page displays "Not supported" under Vulnerabilities for Linux operating systems. This limits visibility into OS-level security risks. It feels like a gap in visibility.
    • @noahtalerman: In the interim, there is no workaround—users cannot see OS vulnerabilities for Linux in the UI, making it harder to prioritize patching efforts.
    • @noahtalerman: Eventually, Fleet could surface Linux OS vulnerabilities on this page, similar to how macOS and Windows vulnerabilities are displayed, allowing admins to prioritize remediation effectively. Fleet could also use language other than "Not supported."
Image
@allenhouchins allenhouchins added :product Product Design department (shows up on 🦢 Drafting board) prospect-universitas labels Mar 4, 2025
@noahtalerman
Copy link
Member

Problem

Fleet is already inventorying and mapping CVE and other vulnerability data for my Linux hosts. However, when I go to Software > OS I am presented with the message Not supported for my Linux operating systems.

What have you tried?

N/A

Potential solutions

Surface vulnerability information on this screen similar to what is already being done for macOS and Windows.

What is the expected workflow as a result of your proposal?

I will no longer see Not supported in the Vulnerabilities column and instead see which of my Linux operating systems have the most vulnerabilities so I can further prioritize remediation or corporate patch policies.

Image

@noahtalerman noahtalerman changed the title Surface number of vulnerabilities for my Linux operating systems Linux OS vulnerabilities (CVEs) Mar 5, 2025
@noahtalerman noahtalerman added ~feature fest Will be reviewed at next Feature Fest ~dogfood Issue resulted from Fleet's product dogfooding. and removed :product Product Design department (shows up on 🦢 Drafting board) labels Mar 5, 2025
@mostlikelee
Copy link
Contributor

The historical reason for this is that our research showed there is no clear concept of OS vulnerabilities on linux, supported by how vulnerabilities are reported in OVAL feeds. An OS is essentially made up of packages and a kernel, both which are reported today in Fleet software.

@lukeheath lukeheath moved this to Ready in 🍽️ Dogfood Mar 20, 2025
@noahtalerman noahtalerman removed the ~feature fest Will be reviewed at next Feature Fest label Mar 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
~dogfood Issue resulted from Fleet's product dogfooding. prospect-universitas
Projects
None yet
Development

No branches or pull requests

3 participants