Earlier quoted context omitted.
> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. It's 2026. We're more than 30 years into the Linux ecosystem. I don't believe this bullshit for a moment. Given how trivially users can implement mitigation, distributions could have done _something_ to protect their users prior to publication date. A handful of messages is all that…
> distributions could have done _something_ to protect their users prior to publication date. yeah, distributions could be following the kernel updates more closely and they would have been patched prior to publication. mainline was patched 30 days before publication. it is not the reporter's responsibility to babysit the linux distributions.
For Linux kernel vulnerabilities, there is no heads-up to distributions
511–520 of 578 posts
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#512Earlier quoted context omitted.
Why would he ever... not release a new version? I don't get what you're trying to say - I'm stating Greg's explicit policy on the topic. If he did something outside of that policy, that wouldn't change anything.
If he doesn't believe in the "concept of vulnerabilities" then it is remarkable that he released a 6.12 targeted on this one fix. Why would he do that otherwise?
As for the latest patch, Greg is currently being forced to clean up a big fucking mess by external parties. And he's miserable about it.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#513Earlier quoted context omitted.
Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…
> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#514Earlier quoted context omitted.
Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…
> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…
> For reference, the standard is 30 for the developer to fix and 90 for it to land on machines.
I’ve never seen that as a standard anywhere.
Are you thinking of this? https://projectzero.google/vulnerability-disclosure-policy.h...
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#515Earlier quoted context omitted.
But now millions more people know about how to exploit it who didn't before. I don't see why you're struggling with this.
You can't bully me into agreeing with you. Why are you struggling with that?
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#516Earlier quoted context omitted.
Is that a rule? Are there rules? These researchers found a vulnerability in the Linux kernel. They could have just written a blog post and put it online, or not told anybody, or sold it. But instead they decided to tell the Linux kernel devs, and give them time to act before publishing. And your beef is that you’ve decided they needed to also inform individual downstream projects that use the Linux kernel? Why? Which…
> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…
Nobody, for what it's worth, is arguing that major distros shouldn't have gotten some kind of notice. The problem is that the entity responsible for doing that isn't the vulnerability research lab. In fact, as a general procedural point, researchers can't go contact downstreams. They might be able to do so in the specific case of Linux, but you've tried to spin that possibility into a binding obligation derived from established practices, which: no. That's not a real thing.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#517Earlier quoted context omitted.
It is literally not the vulnerability researcher's problem to solve or address this.
Brother, it is a simple email to a mailing list. They are professional security researchers, they must know this is the way it is done in the ecosystem. Kicking the can around leads nowhere.
There are (some, loose) norms of vulnerability disclosure, and this isn't one of them.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#518Earlier quoted context omitted.
You're freaking out about the exploit being written in Python and occupying only a small number of bytes. Are you the LLM that wrote Xint's terrible landing page? If so, I have questions.
Oh come on, you know what I'm saying. It's small when written in python, which means any skid can spew it into a server he's got a shell on and get root in 2 seconds. He doesn't need to hope there's already a compiler installed, nor does he need to download some big tool. Just: cat | python3 && su , Ctrl-D And I'm sure it can be refined into something much more likable to the spooky types, if they haven't already don…
The whole thread, really bringing me back to comp.security.unix. I'm not complaining! I miss comp.security.unix.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#519Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#520Earlier quoted context omitted.
None of this impacts disclosure norms. One important reason the clock starts ticking faster once any patch lands is that for serious attackers, the patch discloses the vulnerability. That's quadruply so in 2026, when many orgs are automatically pumping Linux patches through LLM pipelines to qualify them for exploitability. But it's been at least 15 years since "reversing means patches are effectively disclosures legi…
I'm not sure where in my post I challenged existing disclosure norms?