5 ms·
This couldn't be more backwards. This has literally nothing to do with bandwidth. The kernel is a CNA, they are explicitly the ones to do this. The reason they
by staticassertion 5mo ago
This couldn't be more backwards. This has literally nothing to do with bandwidth. The kernel is a CNA, they are explicitly the ones to do this.
The reason they don't is because Linus and Greg have repeatedly, publicly stated that they don't want to because they don't believe that vulnerabilities conceptually make sense for the linux kernel and they refuse to engage in the process.
- bonzini 5mo ago> they don't believe that vulnerabilities conceptually make sense That's exactly what I wrote: "they have a strong belief that all kernel bugs are vulnerabilities and all vulnerabilities are just bugs; sometimes taken to the extreme in both ways". But there is also a question of bandwidth. If a maintainer asks to bring a specific vulnerability to distros-list, the kernel security people will be reasonable. I did it last March.
- nickitolas 5mo agoHow does that square with this comment from greg from today? https://www.openwall.com/lists/oss-security/2026/05/01/3 https://www.openwall.com/lists/oss-security/2026/05/01/3 (About heads up to distros) > Nope, sorry, we are NOT allowed to notify anyone about anything "ahead of time" otherwise we will have to tell everyone about everything. That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it.
- staticassertion 5mo agoHe's full of shit lol
- bonzini 5mo agoI don't know, this is the one that I mentioned: https://www.openwall.com/lists/oss-security/2026/03/30/5 https://www.openwall.com/lists/oss-security/2026/03/30/5 You can see my name under "Timeline", I asked kindly for both distros-list and a longer embargo than usual and got them. I guess Greg is not allowed to notify distros-list, but someone else is?