Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <asLZq3D3HxDMTdz3@netmeister.org>
Date: Sun, 4 Oct 2026 18:56:44 -0400
From: Jan Schaumann <jschauma@...meister.org>
To: oss-security@...ts.openwall.com
Subject: cloud computing provider disclosures

Hello,

I was wondering whether it might make sense to
establish a disclosure list for cloud computing /
virtual private server hosting providers.

The reason that I think this might make sense is that
not every cloud computing provider necessarily offers
their own OS / Linux distribution, and thus may not be
qualified for membership on distros@.

At the same time there are vulnerabilities that
directly and significantly impact cloud computing
providers such that the internet would benefit from
them being able to mitigate prior to disclosure on
e.g., oss-security@.

An obvious example might be disclosure of VM escapes,
which disproportionally impacts such service
providers.

Another option might be to grant cloud computing
providers membership on distros@ even if they do not
offer their own custom Linux distribution.

What do people think?

-Jan

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.