Re: [MAINTAINERS SUMMIT] Scaling our security process
Jiri Kosina <[email protected]> Mon, 27 Jul 2026 19:56:00 +0200 (CEST)
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 27 Jul 2026, Linus Torvalds wrote:
> I refuse to have anything to do with linux-distros.
>
> They have a hard mandatory disclosure policy which I think is completely
> unacceptable. It means that if you send actual exploits to the channel
> those exploits will be made public too. There is absolutely no value in
> that, and it seems completely crazy to me.
>
> Yet exploit code - or at least a PoC - are hugely useful to
> developers. So you do want to have people who figure out some security
> issue - or any other bug, for that matter - to include such code, but
> that does not mean that it should be made public.
I totally agree with you on this, but it's not the case with
linux-distros@ any more. Let me quote Alexander from 2023 [1] specifically
on this:
=====
I've just relaxed the policy on posting exploits. It used to say:
"If you shared exploit(s) that are not an essential part of the issue
description, then at your option you may slightly delay posting them to
oss-security but you must post the exploits to oss-security within at
most 7 days of making the mandatory posting above."
Now it says:
"If you shared exploit(s) that are not an essential part of the issue
description, then at your option you may delay or withhold posting them
to oss-security, and you're encouraged to post the exploits to
oss-security in 1 to 30 days of making the mandatory posting above. The
delay may reasonably match your estimate for independent development of
such exploits."
So it's no longer a requirement ("or withhold" is now an option), and
the recommended delay is now 1 to 30 days (which covers the real-world
range from the old Exim bug to the recent Linux StackRot bug). I also
added a sentence suggesting how to choose the delay.
=====
So it's encouraged (which is still of course questionable), but it's no
longer mandatory and it's up to the reporter's discretion.
[1] https://www.openwall.com/lists/oss-security/2023/09/08/4
--
Jiri Kosina
SUSE Labs