Security bug handling for Hurd glibc
Paul Eggert
eggert@cs.ucla.edu
Tue Aug 4 15:41:20 GMT 2026
On 8/4/26 02:20, Florian Weimer wrote:
> Do you think we need embargoes for Hurd-specific security
> vulnerabilities in glibc?...
>
> Background: Someone ran a poorly aligned AI on RHEL glibc sources, and
> it found a bunch of vulnerabilities in the Hurd part.
I've gotten many such reports for GNU tar, m4, Emacs, etc., and I
haven't bothered with embargoes or coordinating with CERT. The bug
reports were so low-severity (or incorrect) that it wasn't worth the
hassle. Some bug-reporters themselves coordinated with CERT which of
course was fine.
For the Hurd I suspect most bug reports would be in the same category.
More information about the Libc-alpha
mailing list