oss-sec mailing list archives

Re: Linux BlueBorne vulnerabilities


From: Petr Matousek <pmatouse () redhat com>
Date: Thu, 14 Sep 2017 14:12:21 +0200

Hi,

On Wed, Sep 13, 2017 at 09:08:31PM +0000, Armis Security wrote:
We are writing to inform you of two security vulnerabilities we have found
in the Bluetooth stack in Linux (BlueZ).

These vulnerabilities have been made public yesterday (Sept. 12, 2017), and
are part of 8 vulnerabilities we have disclosed to various vendors (as a
group they are called "BlueBorne").

Both Linux-related vulnerabilities where disclosed to
distros () vs openwall org.
The kernel-related vulnerability (CVE-2017-1000251) was also disclosed to
security () kernel org
Both disclosures began on Sept. 5, 2017, and patches were made available
yesterday and today.

at https://www.armis.com/blueborne/, "A Coordinated Disclosure"
paragraph you write that:

"Linux - Contacted August 15 and 17, 2017. On September 5, 2017, we
connected and provided the necessary information to the the Linux kernel
security team and to the Linux distributions security contact list and
conversations followed from there. Targeting updates for on or about
September 12, 2017 for coordinated disclosure."

May you please share with us who was contacted on August 15th and 17th
and why you waited until September 5th with the disclosure to
linux-distros and security () kernel org?

If it was because of the strict embargo rules for linux-distros and
security () kernel org mailing lists, next time please feel free to reach
Red Hat directly via secalert () redhat com . We will honour any reporter
set embargo and can contact other vendors directly. And also work on the
fixes.

Thank you,
-- 
Petr Matousek / Red Hat Product Security
PGP: 0xC44977CA 8107 AF16 A416 F9AF 18F3  D874 3E78 6F42 C449 77CA


Current thread: