oss-sec mailing list archives

Re: Adding Xen.org contact to linux-distros security list


From: Kurt Seifried <kseifried () redhat com>
Date: Fri, 03 Feb 2012 10:02:16 -0700

On 02/03/2012 02:33 AM, Ian Campbell wrote:
Hello,

Would it be possible for myself to be subscribed to the linux-distros
security list as a representative of Xen.org?

Although Xen.org is not a distro we do incorporate upstream software and
one of our upstreams (qemu) uses this list as their embargoed security
announcement channel. We would like to be able to co-ordinate the
release of fixes into our own qemu trees.

Many thanks,

Ian.

I think this is something that should be discussed (I'm not specifically
against Xen joining, but I'm worried about the precedent it might set).
Many projects incorporate upstream software, if we lower the bar of
entry in this respect we may get a lot more people on the list. This
might not be a good idea (more chances of leaks/etc.).

My understanding of the way the vs security list is used is that
upstream is typically notified (after all, they usually are the ones
fixing the issue), and that people not on the list can post to the list
to notify it of upcoming stuff (this happens all the time), we then CC
them on communications about the issue they reported to keep them in the
loop. For something this specific might it not be a better idea for Xen
just go straight to the qemu project so they can be notified of the
embargoed issues?



-- 
Kurt Seifried Red Hat Security Response Team (SRT)


Current thread: