Re: Security bug handling for Hurd glibc
Paul Eggert <[email protected]> Tue, 4 Aug 2026 10:41:20 -0500
| Newsgroups | gmane.os.hurd.cvs |
|---|---|
| Message-ID | <9236acae-54e6-46fb-9ad9-dde818ffc872__42178.2452425518$1785858710$gmane$org@cs.ucla.edu> |
On 8/4/26 02:20, Florian Weimer wrote: > Do you think we need embargoes for Hurd-specific security > vulnerabilities in glibc?... > > Background: Someone ran a poorly aligned AI on RHEL glibc sources, and > it found a bunch of vulnerabilities in the Hurd part. I've gotten many such reports for GNU tar, m4, Emacs, etc., and I haven't bothered with embargoes or coordinating with CERT. The bug reports were so low-severity (or incorrect) that it wasn't worth the hassle. Some bug-reporters themselves coordinated with CERT which of course was fine. For the Hurd I suspect most bug reports would be in the same category.