oss-sec mailing list archives
Re: Linux BlueBorne vulnerabilities
From: Petr Matousek <pmatouse () redhat com>
Date: Thu, 14 Sep 2017 14:12:21 +0200
Hi, On Wed, Sep 13, 2017 at 09:08:31PM +0000, Armis Security wrote:
We are writing to inform you of two security vulnerabilities we have found in the Bluetooth stack in Linux (BlueZ). These vulnerabilities have been made public yesterday (Sept. 12, 2017), and are part of 8 vulnerabilities we have disclosed to various vendors (as a group they are called "BlueBorne"). Both Linux-related vulnerabilities where disclosed to distros () vs openwall org. The kernel-related vulnerability (CVE-2017-1000251) was also disclosed to security () kernel org Both disclosures began on Sept. 5, 2017, and patches were made available yesterday and today.
at https://www.armis.com/blueborne/, "A Coordinated Disclosure" paragraph you write that: "Linux - Contacted August 15 and 17, 2017. On September 5, 2017, we connected and provided the necessary information to the the Linux kernel security team and to the Linux distributions security contact list and conversations followed from there. Targeting updates for on or about September 12, 2017 for coordinated disclosure." May you please share with us who was contacted on August 15th and 17th and why you waited until September 5th with the disclosure to linux-distros and security () kernel org? If it was because of the strict embargo rules for linux-distros and security () kernel org mailing lists, next time please feel free to reach Red Hat directly via secalert () redhat com . We will honour any reporter set embargo and can contact other vendors directly. And also work on the fixes. Thank you, -- Petr Matousek / Red Hat Product Security PGP: 0xC44977CA 8107 AF16 A416 F9AF 18F3 D874 3E78 6F42 C449 77CA
Current thread:
- Linux BlueBorne vulnerabilities Armis Security (Sep 13)
- Re: Linux BlueBorne vulnerabilities Petr Matousek (Sep 14)
- Re: Linux BlueBorne vulnerabilities Armis Security (Sep 14)
- Re: Linux BlueBorne vulnerabilities Solar Designer (Sep 14)
- Re: Linux BlueBorne vulnerabilities Ben Seri (Sep 15)
- Re: Linux BlueBorne vulnerabilities Solar Designer (Sep 15)
- Re: Linux BlueBorne vulnerabilities Ben Seri (Sep 15)
- Re: Linux BlueBorne vulnerabilities Solar Designer (Sep 27)
- Re: Linux BlueBorne vulnerabilities Armis Security (Sep 14)
- Re: Linux BlueBorne vulnerabilities Petr Matousek (Sep 14)