Re: [MAINTAINERS SUMMIT] Scaling our security process

Linus Torvalds <[email protected]> Mon, 27 Jul 2026 10:08:48 -0700
Newsgroups dev.linux.lists.ksummit
Message-ID <CAHk-=wgy3T=jxMy0kv0T1+6M0ahVbmWcXOwWOZU5efo=9U_XMg@mail.gmail.com>
On Mon, 27 Jul 2026 at 07:37, Jiri Kosina <[email protected]> wrote:
>
> Well, linux-distros@ is still there, and is used to coordinate security
> fixes in exactly this way consistently for vast majority of all the
> relevant projects, pretty much except for the kernel. With my distro hat
> on, I'd add "unfortunately".

I refuse to have anything to do with linux-distros.

They have a hard mandatory disclosure policy, which I think is
completely unacceptable. It means that if you send actual exploits to
the channel those exploits will be made public too. There is
absolutely no value in that, and it seems completely crazy to me.

Yet exploit code - or at least a PoC - are hugely useful to
developers. So you do want to have people who figure out some security
issue - or any other bug, for that matter - to include such code, but
that does not mean that it should be made public.

The *fix* obviously should be public, and the commit message needs to
explain the bug. And the threat of mandatory disclosure for any
unfixed bug is a good way to keep people honest. But disclosing
exploits after-the-fact as if everybody will have immediately
upgraded? Asinine.

"Linux-distros - just say no"

                Linus