From mboxrd@z Thu Jan 1 00:00:00 1970 Reply-To: kernel-hardening@lists.openwall.com Date: Wed, 20 Jan 2016 18:48:08 +0100 From: Hanno =?UTF-8?B?QsO2Y2s=?= Message-ID: <20160120184808.3a5c6d26@pc1> In-Reply-To: References: <20160119112812.GA10818@mwanda> <20160119124917.6058019b@pc1> <20160120121958.4a392837@pc1> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="=_zucker.schokokeks.org-4002-1453312049-0001-2" Subject: Re: [kernel-hardening] 2015 kernel CVEs To: kernel-hardening@lists.openwall.com List-ID: This is a MIME-formatted message. If you see this text it means that your E-mail software does not support MIME-formatted messages. --=_zucker.schokokeks.org-4002-1453312049-0001-2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Wed, 20 Jan 2016 14:15:14 +0000 Wade Mealing wrote: > I'm all about improving process, I imagine I would have done the same > steps. What changes to the responses would need to be made to be > less limited ? Understand that i'm not taking this personally and > consider this an opportunity for Red Hat Security to improve as a > group. Just to make this clear, I was not involved at all. I based my statement purely on publicly available information from the advisory that says: "We unsuccessfully tried to contact the vendor for several months. We never received any response on our bugtraq ticket:" So I'm not the right person to discuss what went wrong in the process. FWIW I tried to reach out to one of the people doing this research (Sergej Schumilo) and hope we can make sure these issues get tackled. --=20 Hanno B=C3=B6ck http://hboeck.de/ mail/jabber: hanno@hboeck.de GPG: BBB51E42 --=_zucker.schokokeks.org-4002-1453312049-0001-2 Content-Type: application/pgp-signature Content-Transfer-Encoding: 7bit Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJWn8hYAAoJEKWIAHK7tR5C18IP/1o5brluQstwPiCnWvxJPF4Z 3Nc9wTuDAtUKKL78FYBHl4kkUaKJF8XuEtqZAhz1qJG4LomnImpGeRpkdg1ZPPCL /Tb3wLEZ8Lwrnoxp0h8zrK+sgG7a5Jib3WN+49LS+xwUzigbUvcvTrbVORcMDRWx 0/P6TG5aZ2bFph0KtKmyCvFLFV1JjTI8RPwKRqlvxcMn1dRWGNHxPz7HQUcqFlng 9P/nPuwhEGDzEevWWPHa0sIK1owa598QNG8ldhzSUrxWrCU3BGUhA0z17v8h5MAK f579UN3wR41NSjAVV+HfBZEndK9HzXsb86a1N2BEjNCpYZfwML45Eew+ZOdFPcBl JDBsStmYXeo/TO8Up+l2yHo/0UewZ0ZP9monT16bDrl9ou6pQbNf9lj7N5zraTKB j00mlK5QMMxjjBkMSHadIOV6fZ6lBg51n0C1vALPZdT+6THA9cE1kp1AJbuoodVF Y1CDr4b8OjWkE/FGkkcK31g6n6WBhQyBb/OIdoAPRRbt7gK1efW2HP621IoniQiG 7aLeiJjb6gyrN4fMZG6s/zSmGda6aSI2r4RfR6U5m50pt5MnNJs0cwPGUq0EBMVn T708lt8WBz3oLK8IjDv5mBHjMe+1sc5KQY1Z65Nz2OkhDfF+ThRh8UjiH5Oy6HLj l1IZ8rrfmYL8jmFF6b6N =120v -----END PGP SIGNATURE----- --=_zucker.schokokeks.org-4002-1453312049-0001-2--