GNU C Library as its own CNA?

Siddhesh Poyarekar siddhesh@gotplt.org
Fri Jul 28 16:11:33 GMT 2023


On 2023-07-28 12:09, Florian Weimer wrote:
> * Siddhesh Poyarekar:
> 
>> At the outset, we'll need to have broad agreement on the following:
>>
>> 1. How should users submit issues?  We would need an independent,
>> private mailing list, possibly one that can also do PGP for users to
>> report security issues.
>>
>> 2. Identify a group of people who ought to be on that list.  A
>> starting group could be a cross section of named maintainers from
>> various distributions and FSF stewards but we probably need a way to
>> make sure that the group is inclusive without being too broad.
>>
>> 3. A formal representation to the root CNA, i.e. Red Hat.  We would
>> need a group of volunteers that would be willing to step in as signees
>> for this.  I'm in, but I can't do it alone and would need more
>> volunteers; it could perhaps be the same set of people who would be
>> part of the initial security team in (2).
> 
> I think the CNA rules sort of assume that a CNA issues security
> advisories:
> 
>    <https://www.cve.org/ResourcesSupport/AllResources/CNARules>
> 
> So we'd have to start doing that, too.

Yes, and we would have to honour some SLAs for the entire process, from 
acknowledging CVEs to making them public.  I reckon we could still rely 
on some help from distro maintainers for some of this coordination.

Sid


More information about the Libc-alpha mailing list