Tout à fait. D'ailleurs le fin mot de l'histoire revient à Linus:
----------------------
On Thu, 6 Nov 2003, bert hubert wrote:
>
> And, was there any route via which this malicious patch could've worked
> itself into a kernel release?
No. There are two ways to get into a kernel release: patches to me by
email (which depending on the person get more or less detailed scrutiny,
but core files would definitely get a read-through and need an
explanation), and through BK merges.
And the people who merge with BK wouldn't have used the CVS tree.
[^] # Re: On se calme! On n'est pas (encore) Slashdot
Posté par oliv . En réponse à la dépêche Tentative d'insertion d'une porte dérobée dans le noyau Linux. Évalué à 4.
----------------------
On Thu, 6 Nov 2003, bert hubert wrote:
>
> And, was there any route via which this malicious patch could've worked
> itself into a kernel release?
No. There are two ways to get into a kernel release: patches to me by
email (which depending on the person get more or less detailed scrutiny,
but core files would definitely get a read-through and need an
explanation), and through BK merges.
And the people who merge with BK wouldn't have used the CVS tree.
Linus
-----------------------
( http://marc.theaimsgroup.com/?l=linux-kernel&m=106813487330283&(...) )
Bref Linus qui n'est pas un j'menfoutiste au niveau de la sécurité conclut clairement que ce patch n'avait AUCUNE chance de se retrouver inclus dans le code de Linux.