Re: [MAINTAINERS SUMMIT] Scaling our security process

Jiri Kosina <[email protected]> Mon, 27 Jul 2026 19:56:00 +0200 (CEST)
Newsgroups dev.linux.lists.ksummit
Message-ID <[email protected]>
On Mon, 27 Jul 2026, Linus Torvalds wrote:

> I refuse to have anything to do with linux-distros.
> 
> They have a hard mandatory disclosure policy which I think is completely 
> unacceptable. It means that if you send actual exploits to the channel 
> those exploits will be made public too. There is absolutely no value in 
> that, and it seems completely crazy to me.
> 
> Yet exploit code - or at least a PoC - are hugely useful to
> developers. So you do want to have people who figure out some security
> issue - or any other bug, for that matter - to include such code, but
> that does not mean that it should be made public.

I totally agree with you on this, but it's not the case with 
linux-distros@ any more. Let me quote Alexander from 2023 [1] specifically 
on this:

=====
I've just relaxed the policy on posting exploits.  It used to say:

"If you shared exploit(s) that are not an essential part of the issue
description, then at your option you may slightly delay posting them to
oss-security but you must post the exploits to oss-security within at
most 7 days of making the mandatory posting above."

Now it says:

"If you shared exploit(s) that are not an essential part of the issue
description, then at your option you may delay or withhold posting them
to oss-security, and you're encouraged to post the exploits to
oss-security in 1 to 30 days of making the mandatory posting above. The
delay may reasonably match your estimate for independent development of
such exploits."

So it's no longer a requirement ("or withhold" is now an option), and
the recommended delay is now 1 to 30 days (which covers the real-world
range from the old Exim bug to the recent Linux StackRot bug).  I also
added a sentence suggesting how to choose the delay.
=====

So it's encouraged (which is still of course questionable), but it's no 
longer mandatory and it's up to the reporter's discretion.

[1] https://www.openwall.com/lists/oss-security/2023/09/08/4

-- 
Jiri Kosina
SUSE Labs