Re: Proper procedure for reporting possible security vulnerabilities?

From: Chris Wright
Date: Mon Jan 10 2005 - 20:27:05 EST


* Diego Calleja (diegocg@xxxxxxxxx) wrote:
> El Mon, 10 Jan 2005 16:40:02 -0800 Chris Wright <chrisw@xxxxxxxx> escribió:
>
> > Problem is, the rest of the world uses a security contact for reporting
> > security sensitive bugs to project maintainers and coordinating
> > disclosures. I think it would be good for the kernel to do that as well.
>
> (somewhat OT..)
>
> Perhaps it's just me, but i think it'd be nice that a new kernel version is
> released every time a security issue is found.

I agree. I'd not mind seeing a full release, but at least a collection
of relevant patches. I used to keep such a list, and have discussed
bringing it back with some folks (just for the current stable 2.6.x).
I think there's some agreement that we could do better.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/