logoalt Hacker News

aduwahyesterday at 7:04 PM2 repliesview on HN

Especially since the reporter is explicitly asked not to notify the distro teams first.

https://docs.kernel.org/process/security-bugs.html

```As such, the kernel security team strongly recommends that as a reporter of a potential security issue you DO NOT contact the “linux-distros” mailing list UNTIL a fix is accepted by the affected code’s maintainers and you have read the distros wiki page above and you fully understand the requirements that contacting “linux-distros” will impose on you and the kernel community. ```


Replies

nubinetworkyesterday at 10:06 PM

I don't get why the initial reporter should have to do that legwork. The kernel maintainers should be doing that.

show 1 reply
stonogoyesterday at 8:04 PM

The kernel team has been at odds with the CVE process and the oss-security community about this stuff for many, many years now. It's a big part of why the kernel team established a CNA and started flooding CVE notifications; they don't believe that security problems are different than non-security problems, and refuse to establish norms or policies based on the idea that they are.

show 2 replies