Reporting-vulnerabilities

From Driver Backports Wiki
(Difference between revisions)
Jump to: navigation, search
(Created page with " <h2>Reporting security vulnerabilities</h2> If you have a security vulnerabilities issue to report and you know it is backports related you can report this directly to the m...")
 
(Move content to Documentation/reporting-bugs and redirect)
Line 1: Line 1:
 
+
#REDIRECT [[Documentation/reporting-bugs]]
<h2>Reporting security vulnerabilities</h2>
+
 
+
If you have a security vulnerabilities issue to report and you know it is backports related you can report this directly to the maintainers:
+
 
+
  * hauke@hauke-m.de, mcgrof@kernel.org, johannes@sipsolutions.net
+
 
+
The report will be handled in private, once the issue is fixed and propagated to users, the security fix will be disclosed and documented. As of date we have had no security vulnerabilities issues reported. Until then this page can be used to track updates on vulnerabilities related to Linux backports. The attack surface to Linux backports consists about 1-2% of code, this varies depending on what kernel you are on. The older kernel you are on the higher the security risk. Security issues on Linux should affect users of Linux backports if the code is carried over into backports, fixes for that are addressed through new release of backports with the corresponding upstream fixes. Security fixes for Linux belong upstream on Linux, not on Linux backports. To learn how to report Linux kernel security issues refer to [https://www.kernel.org/doc/Documentation/SecurityBugs SecurityBugs documentation].
+

Revision as of 01:21, 25 June 2017

  1. REDIRECT Documentation/reporting-bugs
Personal tools