Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Greg KH <greg@...>
Cc: Andrew Morton <akpm@...>, <torvalds@...>, <linux-kernel@...>, <stable@...>
Date: Monday, July 14, 2008 - 10:14 pm

On 14 Jul 2008 at 5:04, Greg KH wrote:


a collective one, i take it, as noone else bothered to respond either ;).

anyway, you must have been at an interesting place i suppose as you
even managed to slip a mail through a wormhole that somehow arrived
here on 8th ;).


they're very relevant and rather long, you should take your time and read
them whenever you're back on the normal net. or you can do like RMS and
surf the web through email ;).


so it's full disclosure for both vanilla and -stable, there's no difference?
just because at the end of your mail you say:


now are they totally different or not? ;)

in any case, you say the full disclosure policy applies. what does that mean
for you? does it mean omitting security impact information you know about
(not 'here is a working exploit' but 'this is a buffer overflow' or 'this
is an exploitable bug')? because such omissions have repeatedly occured for
the past many years (you'll find several examples pointed out at those LWN
URLs) and they're hard to reconcile with your declared disclosure policy.


do you also omit any of the usual security related words, such as, say,
'buffer overflow', 'security' when describing a bug? say, look at today's
2.6.25.11 and its single fix that doesn't say anything about 'security',
heck, not even its announcement does. do you think it's what constitutes
full disclosure? ;)


you at least add CVE IDs on occasion, mainline commits are even worse in
that regard.


yes, the real and more important problem is with the mainline development
itself, you're mostly suffering collateral damage, so to speak. but since
you're also part of that development process, you can't hide behind that.

so guys (meaning not only Greg but Andrew, Linus, et al.), when will you
publicly explain why you're covering up security impact of bugs? and even
more importantly, when will you change your policy or bring your process
in line with what you declared?

cheers,
  PaX Team

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 1:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 1:29 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 3:54 am)
Re: Linux 2.6.25.10, Greg KH, (Tue Jul 8, 12:12 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 2:57 pm)
Re: Linux 2.6.25.10, , (Thu Jul 3, 3:31 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 8:04 am)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 8:47 pm)
RE: [stable] Linux 2.6.25.10, , (Fri Jul 18, 9:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 9:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Sat Jul 19, 1:41 am)
Re: [stable] Linux 2.6.25.10, , (Mon Jul 14, 10:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 10:27 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:15 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 9:13 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:34 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 11:31 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 2:33 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 6:39 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 6:47 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:22 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:35 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:08 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:21 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:07 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 3:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 3:16 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:13 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 5:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)