Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <aEROmObEfB-k2IW7@lappy>
Date: Sat, 7 Jun 2025 10:37:12 -0400
From: Sasha Levin <sashal@...nel.org>
To: oss-security@...ts.openwall.com
Cc: eschwartz@...too.org
Subject: Re: Re: Re: Linux kernel: HFS+ filesystem
 implementation, issues, exposure in distros

On Sat, Jun 07, 2025 at 10:17:08AM +0200, Greg KH wrote:
>On Fri, Jun 06, 2025 at 06:00:09PM +0200, Attila Szasz wrote:
>> I don't see how Canonical Product Security is a bad actor here for caring
>> about the actual security of downstream users and acting in a timely
>> manner about an issue that they considered to impact Ubuntu Linux,
>> correctly.
>>
>> Canonical has a scope of
>> "All Canonical issues (including Ubuntu Linux) only."
>>
>> kernel.rg has a scope of
>> "Any vulnerabilities in the Linux kernel as listed on kernel.org, excluding
>> end-of-life (EOL) versions."
>>
>> Both of them were contacted.
>
>For the record, the CNA for kernel.org was NOT contacted here at all for
>this issue.  You sent a message to security@...nel.org, NOT
>cve@...nel.org.  security@k.o has nothing to do with CVE assignments and
>is NOT responsible for the kernel.org CNA.  Our documentation should
>state this very clearly, if not, we will be glad to update it where
>needed, just let us know.

The scope, which I assume was quoted from
https://www.cve.org/PartnerInformation/ListofPartners/partner/Linux also
lists cve@...nel.org as the right email to contact.

Note that this isn't just a technicality: for example, I'm a member of
cve@k.o, but *NOT* of security@....

The first I learned of this issue was your Linkedin post[1] after this
was already assigned a CVE from Canonical.


[1] https://www.linkedin.com/posts/attila-sz%C3%A1sz-086abb122_ssd-advisory-linux-kernel-hfsplus-slab-out-of-bounds-activity-7307735032729690113-Y8uY

-- 
Thanks,
Sasha

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.