For Linux kernel vulnerabilities, there is no heads-up to distributions
161–170 of 578 posts
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#162> Note that for Linux kernel vulnerabilities, unless the reporter chooses to bring it to the linux-distros ML, there is no heads-up to distributions. Why would they imply it is incumbent on the reporter to liaise with distributions? That seems to assume a high level of familiarity with the linux project. Vulnerability reporters shouldn’t be responsible for directly working with every downstream consumer of the linux…
The reporter made a website explicitly calling out Ubuntu, RedHat, Amazon, and SUSE but didn’t notify them, and you think that’s reasonable? That they might not have known those distributions are downstream from the kernel team?
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#163Earlier quoted context omitted.
So if I found a vulnerability that lets hackers withdraw withdraw all the money in your account without a trail on where the money went, you'd be fine with them disclosing it to the public at the same time as the bank learns about it? Even when there is no known use case of the attack (other than the security researcher's)? > The vulnerability exists for me either way, and I'd rather have the chance to know about it…
Yep, I'd be fine with that. My bank has insurance, and my money would be returned.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#164Hey Xint Code / tylerni7 https://news.ycombinator.com/threads?id=tylerni7 >, maybe you should improve your disclosure process as well? Maybe make it mandatory for users of your tool?
its the same disclosure policy as google's project zero, and several other major players, so you should probably be trying to ping a lot more people
reporters should not be responsible for finding out and individually reporting to every downstream consumer. blame the kernel security team, who is in a much better position to coordinate notifications to individual distro security teams.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#165Earlier quoted context omitted.
Does it? Now that I see their name again in this context they're blacklisted for life.
Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#166Earlier quoted context omitted.
Does it? Now that I see their name again in this context they're blacklisted for life.
Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#167Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#168Earlier quoted context omitted.
Your advertising for them on HN would help them too, I bet.
Does it? Now that I see their name again in this context they're blacklisted for life.
this was a failure of the kernel security team, and their stance on communicating security issues with their downstreams.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#169Earlier quoted context omitted.
Does it? Now that I see their name again in this context they're blacklisted for life.
Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#170For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…
I'd consider a shared hoster which allows users to run their own (native) code and doesn't use VMs for tenant isolation extremely irresponsible in 2026.