A fuzzy issue of responsible disclosure
A fuzzy issue of responsible disclosure
Posted Aug 16, 2022 20:48 UTC (Tue) by mcatanzaro (subscriber, #93033)In reply to: A fuzzy issue of responsible disclosure by Wol
Parent article: A fuzzy issue of responsible disclosure
The comments on this story might themselves be worthy of an LWN story. Claiming that reporting *legitimate* security bugs is akin to harassment is pretty wild. I don't think anybody expects you to fix all those bugs, but the public deserves to know about them, and it's hard to think of a better place than the upstream bug tracker. I suppose there are plenty of other ways researchers can report vulnerabilities if you don't want your bug tracker used that purpose, though.
Ideally, they would receive CVEs so they can be tracked, but we all know only a tiny minority of security vulnerabilities actually receive CVEs.
It's unusual to receive the quantity of fuzzer reports that you are receiving. It indicates a very serious safety problem. Even web engines, which are full of vulnerabilities and fuzzed regularly by security researchers, do not deal with anywhere near that many fuzzer reports.
