oss-sec mailing list archives

Re: CVE request - Linux kernel: VFAT slab-based buffer overflow


From: Greg KH <greg () kroah com>
Date: Wed, 27 Feb 2013 08:17:26 -0800

On Wed, Feb 27, 2013 at 02:59:17PM +0000, Benji wrote:
Ah the logic. Open source software, hidden secret hush hush no public
reporting patches.

Every single patch we make to the kernel is public, it is up to you to
determine if you feel it is a "security fix" or not.  And to do so is a
non-trivial task, something that I sure don't want to be responsible for
trying to do.  And since no one else has ever stepped up to want to do
it either, there's not much more that can be done.

Are you willing to do it?

greg k-h


Current thread: