Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <asOd-W8IsF9rt9Vt@netmeister.org>
Date: Mon, 5 Oct 2026 08:54:17 -0400
From: Jan Schaumann <jschauma@...meister.org>
To: oss-security@...ts.openwall.com
Subject: Re: cloud computing provider disclosures

Demi Marie Obenour <demiobenour@...il.com> wrote:
> On 10/4/26 18:56, Jan Schaumann wrote:

> > I was wondering whether it might make sense to
> > establish a disclosure list for cloud computing /
> > virtual private server hosting providers.

> - Xen Project already has its own predisclosure list.
> - KVM (sadly) falls under the Linux kernel security process.
> - Cloud Hypervisor and QEMU have their own processes.
> - Not sure about Firecracker.

I think this somewhat helps make my point: cloud
compute providers may use several of those, but not
consistently (or at all) receive advanced
notifications.

Centralizing this (with, agreed, some definitions of
who qualifies to be determined) would also make it
easier for researchers to responsibly disclose.

The linux kernel disclosure path is currently rather
suboptimal, with urgent and actionable vulnerabilities
easily getting buried under hundreds of non-actionable
or non-urgent fixes.


Having said that, while I'm sympathetic to Aaron's
points (minimize likelihood of possible leaks;
providers ought to be able to act quickly), having
even a few days to get your ducks in a row before
the hype circus kicks off of some social media and
company blog post would indeed be nice.

-Jan

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.