Re: [MAINTAINERS SUMMIT] Scaling our security process
Linus Torvalds <[email protected]> Mon, 27 Jul 2026 10:08:48 -0700
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <CAHk-=wgy3T=jxMy0kv0T1+6M0ahVbmWcXOwWOZU5efo=9U_XMg@mail.gmail.com> |
On Mon, 27 Jul 2026 at 07:37, Jiri Kosina <[email protected]> wrote: > > Well, linux-distros@ is still there, and is used to coordinate security > fixes in exactly this way consistently for vast majority of all the > relevant projects, pretty much except for the kernel. With my distro hat > on, I'd add "unfortunately". I refuse to have anything to do with linux-distros. They have a hard mandatory disclosure policy, which I think is completely unacceptable. It means that if you send actual exploits to the channel those exploits will be made public too. There is absolutely no value in that, and it seems completely crazy to me. Yet exploit code - or at least a PoC - are hugely useful to developers. So you do want to have people who figure out some security issue - or any other bug, for that matter - to include such code, but that does not mean that it should be made public. The *fix* obviously should be public, and the commit message needs to explain the bug. And the threat of mandatory disclosure for any unfixed bug is a good way to keep people honest. But disclosing exploits after-the-fact as if everybody will have immediately upgraded? Asinine. "Linux-distros - just say no" Linus