Linux
Welcome to c/linux!
Welcome to our thriving Linux community! Whether you're a seasoned Linux enthusiast or just starting your journey, we're excited to have you here. Explore, learn, and collaborate with like-minded individuals who share a passion for open-source software and the endless possibilities it offers. Together, let's dive into the world of Linux and embrace the power of freedom, customization, and innovation. Enjoy your stay and feel free to join the vibrant discussions that await you!
Rules:
-
Stay on topic: Posts and discussions should be related to Linux, open source software, and related technologies.
-
Be respectful: Treat fellow community members with respect and courtesy.
-
Quality over quantity: Share informative and thought-provoking content.
-
No spam or self-promotion: Avoid excessive self-promotion or spamming.
-
No NSFW adult content
-
Follow general lemmy guidelines.
view the rest of the comments
According to comments on Lobsters, the distros weren't notified prior to publication, so any backports took longer than usual.
I dont get it, doesn't responsible disclosure mean the distros get the packages out first?
Nothing about this disclosure was responsible.
https://xint.io/blog/copy-fail-linux-distributions#coordinated-disclosure-timeline-8
It was patched a month ago.
According to Greg K-H, nobody typically gets notified by the Linux kernel team about anything, so this is not abnormal: https://www.openwall.com/lists/oss-security/2026/05/01/3
Distro maintainers should be monitoring the lists and feeds and making decisions themselves, not expecting spoon-feeding from the kernel team.
Yes, but the researchers should have notified the linux-distros mailing list as well per the published policy. See https://docs.kernel.org/process/security-bugs.html#coordination-with-other-groups
It's unfortunate, but understandable why this didn't happen. Still, the researchers claimed in their blog post that fixes were shipping, apparently without actually checking.
It sounds like what you're describing and what the email thread are discussing are pretty different. The email thread was asking to know about things prior to disclosure. You seem to be saying that they should have directly notified the distros list when the fix was up instead of just posting the article or whatever on their site. Two very different discussions.