Security web page

Florian Weimer fw@deneb.enyo.de
Fri Jun 27 20:20:27 GMT 2025


We currently have this:

| As a rule of thumb, security vulnerabilities which are exposed over
| the network or can be used for local privilege escalation (through
| existing applications, not synthetic test cases) should be reported
| privately. We expect that such critical security bugs are rare, and
| that most security bugs can be reported in Bugzilla, thus making
| them public immediately. If in doubt, you can file a private bug. /

<https://sourceware.org/glibc/security.html>

The trailing / is in the original.  The real problem is the sentence
before it.  You cannot file private security bugs.  What is probably
meant is “If in doubt, report the issue privately, as indicated below”
or similar.


More information about the Libc-alpha mailing list