Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

161–170 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#162

> Note that for Linux kernel vulnerabilities, unless the reporter chooses to bring it to the linux-distros ML, there is no heads-up to distributions. Why would they imply it is incumbent on the reporter to liaise with distributions? That seems to assume a high level of familiarity with the linux project. Vulnerability reporters shouldn’t be responsible for directly working with every downstream consumer of the linux…

The reporter made a website explicitly calling out Ubuntu, RedHat, Amazon, and SUSE but didn’t notify them, and you think that’s reasonable? That they might not have known those distributions are downstream from the kernel team?

What is the heuristic for who should get the heads up? Should they notify amazon but not google simply because they named amazon linux in the report? Seems to me the answer to my first question gets messy fast.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#163
post #116

Earlier quoted context omitted.

So if I found a vulnerability that lets hackers withdraw withdraw all the money in your account without a trail on where the money went, you'd be fine with them disclosing it to the public at the same time as the bank learns about it? Even when there is no known use case of the attack (other than the security researcher's)? > The vulnerability exists for me either way, and I'd rather have the chance to know about it…

Yep, I'd be fine with that. My bank has insurance, and my money would be returned.

The banks cost of insurance goes up, cost of running an account goes up, how do we correct for this? offer worse accounts to customers...

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#164

Hey Xint Code / tylerni7 https://news.ycombinator.com/threads?id=tylerni7 >, maybe you should improve your disclosure process as well? Maybe make it mandatory for users of your tool?

they disclosed 30 days after the patch was merged in the thing they reported to.

its the same disclosure policy as google's project zero, and several other major players, so you should probably be trying to ping a lot more people

reporters should not be responsible for finding out and individually reporting to every downstream consumer. blame the kernel security team, who is in a much better position to coordinate notifications to individual distro security teams.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#165

Earlier quoted context omitted.

Does it? Now that I see their name again in this context they're blacklisted for life.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#166

Earlier quoted context omitted.

Does it? Now that I see their name again in this context they're blacklisted for life.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#168
post #32

Earlier quoted context omitted.

Your advertising for them on HN would help them too, I bet.

Does it? Now that I see their name again in this context they're blacklisted for life.

hope you are also blacklisting google's project zero, and practically every other major player in the vulnerability reporting space, as all use roughly the same bog standard 90+30 policy.

this was a failure of the kernel security team, and their stance on communicating security issues with their downstreams.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#169

Earlier quoted context omitted.

Does it? Now that I see their name again in this context they're blacklisted for life.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

[flagged]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#170

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

> Who knows how many shared hosting providers were hacked with this.

I'd consider a shared hoster which allows users to run their own (native) code and doesn't use VMs for tenant isolation extremely irresponsible in 2026.

Post reply on HN