summaryrefslogtreecommitdiffstats
diff options
authorChris Feyerchak <anonymous.contributor@example.org>2017-06-25 01:19:34 +0000
committerKonstantin Ryabitsev <konstantin@linuxfoundation.org>2024-10-04 15:47:33 -0400
commitc4d9cd93eaaeeffd17e3ca62bc03c7424f59f9ad (patch)
tree9f828df8ab3e2bade7a1c8ebfe5f10a1da8c60c5
parent8c4f623443145e4e8bd0bfd4d5c75fe92038ac5b (diff)
downloadbackports-c4d9cd93eaaeeffd17e3ca62bc03c7424f59f9ad.tar.gz
Move "Reporting security vulnerabilites" from other page
-rw-r--r--wiki/Bugs.mediawiki8
1 files changed, 8 insertions, 0 deletions
diff --git a/wiki/Bugs.mediawiki b/wiki/Bugs.mediawiki
index eeec23b..e721e01 100644
--- a/wiki/Bugs.mediawiki
+++ b/wiki/Bugs.mediawiki
@@ -14,6 +14,14 @@ Always use: '''backports@vger.kernel.org''' and then use one of the following ma
* wireless: linux-wireless@vger.kernel.org
* ethernet: netdev@vger.kernel.org
+<h1>Reporting security vulnerabilities</h1>
+
+If you have a security vulnerabilities issue to report and you know it is backports related you can report this directly to the maintainers:
+
+ * hauke@hauke-m.de, mcgrof@kernel.org, johannes@sipsolutions.net
+
+The report will be handled in private, once the issue is fixed and propagated to users, the security fix will be disclosed and documented. As of date we have had no security vulnerabilities issues reported. Until then this page can be used to track updates on vulnerabilities related to Linux backports. The attack surface to Linux backports consists about 1-2% of code, this varies depending on what kernel you are on. The older kernel you are on the higher the security risk. Security issues on Linux should affect users of Linux backports if the code is carried over into backports, fixes for that are addressed through new release of backports with the corresponding upstream fixes. Security fixes for Linux belong upstream on Linux, not on Linux backports. To learn how to report Linux kernel security issues refer to [https://www.kernel.org/doc/Documentation/SecurityBugs SecurityBugs documentation].
+
<h1>Backports bugzilla</h1>
For future reference: [[bugzilla|backports bugzilla]]