Re: Security bug handling for Hurd glibc

Samuel Thibault <[email protected]> Tue, 4 Aug 2026 23:29:31 +0200
Newsgroups gmane.os.hurd.cvs,gmane.comp.lib.glibc.alpha
Organization I am not organized
Message-ID <anJZu0T3SVI-ZpAH@end>
Hello,

Paul Eggert, le mar. 04 août 2026 10:41:20 -0500, a ecrit:
> On 8/4/26 02:20, Florian Weimer wrote:
> > Do you think we need embargoes for Hurd-specific security
> > vulnerabilities in glibc?...
> > 
> > Background: Someone ran a poorly aligned AI on RHEL glibc sources, and
> > it found a bunch of vulnerabilities in the Hurd part.
> 
> I've gotten many such reports for GNU tar, m4, Emacs, etc., and I haven't
> bothered with embargoes or coordinating with CERT. The bug reports were so
> low-severity (or incorrect) that it wasn't worth the hassle. Some
> bug-reporters themselves coordinated with CERT which of course was fine.
> 
> For the Hurd I suspect most bug reports would be in the same category.

Yes, probably not worth going with an embargo.

Samuel