[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] Linux 4.19.0-rc3 Bluetooth out-of-bounds-read and use-after-free
From:       Greg KH <greg () kroah ! com>
Date:       2018-10-31 21:00:23
Message-ID: 20181031210023.GF4132 () kroah ! com
[Download RAW message or body]

On Wed, Oct 31, 2018 at 03:11:38PM +0100, Solar Designer wrote:
> As you can see below, in one message the sender offered to coordinate
> with security@k.o and asked for a CVE ID.  However, this was in response
> to my questions about those aspects as it relates to the sender's other
> message, and I don't know whether the sender actually proceeded to
> coordinate with security@k.o (I tried asking the sender and got no
> response) and no CVE ID was assigned by distros (since the sender also
> didn't respond to my inquiry about security relevance).

security@k.o generally tells all people who submit syzbot reports to
just contact the upstream developers on their mailing list for issues
reported by that tool, as that is what the tool's team does.

And I think we did that for this report as well, but never heard
anything back :(

thanks,

greg k-h
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic