LWN.net Logo

Another old security problem

Another old security problem

Posted Sep 10, 2010 20:23 UTC (Fri) by gregkh (subscriber, #8)
In reply to: Another old security problem by spender
Parent article: Another old security problem

> With the general upstream attitude and handling of security bugs, on
> principle I don't email vendor-sec or security@.

That's sad, as security@kernel.org is the only group that will guarantee
that we will look at the issue and work to resolve it in a quick manner.

> Is it only a problem when the shoe's on the other foot?

No, I was worried that something got reported to security@kernel.org
that we did not respond to in a timely manner.

If you notify random kernel developers, one of whom is not part of the
kernel security team, then we can't guarantee any type of response.
Which, sadly, seems to be the case here. Otherwise the problem would
have been resolved a long time ago.

In the future, it would be great if you could notify security@kernel.org
about these types of problems so that they can be handled properly.

thanks.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds