blob: 10a1f79376a2ecc5491dd7225e58ec3bdba3a6f7 [file] [log] [blame]
Mauro Carvalho Chehab1d7078d2016-09-19 08:07:49 -03001Security bugs
2=============
3
Linus Torvalds1da177e2005-04-16 15:20:36 -07004Linux kernel developers take security very seriously. As such, we'd
5like to know when a security bug is found so that it can be fixed and
6disclosed as quickly as possible. Please report security bugs to the
7Linux kernel security team.
8
91) Contact
Mauro Carvalho Chehab1d7078d2016-09-19 08:07:49 -030010----------
Linus Torvalds1da177e2005-04-16 15:20:36 -070011
12The Linux kernel security team can be contacted by email at
13<security@kernel.org>. This is a private list of security officers
14who will help verify the bug report and develop and release a fix.
15It is possible that the security team will bring in extra help from
16area maintainers to understand and fix the security vulnerability.
17
18As it is with any bug, the more information provided the easier it
19will be to diagnose and fix. Please review the procedure outlined in
20REPORTING-BUGS if you are unclear about what information is helpful.
21Any exploit code is very helpful and will not be released without
22consent from the reporter unless it has already been made public.
23
242) Disclosure
Mauro Carvalho Chehab1d7078d2016-09-19 08:07:49 -030025-------------
Linus Torvalds1da177e2005-04-16 15:20:36 -070026
27The goal of the Linux kernel security team is to work with the
28bug submitter to bug resolution as well as disclosure. We prefer
29to fully disclose the bug as soon as possible. It is reasonable to
30delay disclosure when the bug or the fix is not yet fully understood,
31the solution is not well-tested or for vendor coordination. However, we
32expect these delays to be short, measurable in days, not weeks or months.
33A disclosure date is negotiated by the security team working with the
34bug submitter as well as vendors. However, the kernel security team
35holds the final say when setting a disclosure date. The timeframe for
Lucas De Marchi25985ed2011-03-30 22:57:33 -030036disclosure is from immediate (esp. if it's already publicly known)
Linus Torvalds1da177e2005-04-16 15:20:36 -070037to a few weeks. As a basic default policy, we expect report date to
38disclosure date to be on the order of 7 days.
39
403) Non-disclosure agreements
Mauro Carvalho Chehab1d7078d2016-09-19 08:07:49 -030041----------------------------
Linus Torvalds1da177e2005-04-16 15:20:36 -070042
43The Linux kernel security team is not a formal body and therefore unable
44to enter any non-disclosure agreements.