Give an overview of the full process the start of the document. This makes it clear 1) in what order the lists should be contacted, and 2) the purpose of each list. Thanks to Jonathan Corbet and Mauro Carvalho Chehab for providing the readable markup for the table. Link: https://lore.kernel.org/all/20220604014317.79eb23db@xxxxxxx/ Suggested-by: Jonathan Corbet <corbet@xxxxxxx> Suggested-by: Mauro Carvalho Chehab <mchehab@xxxxxxxxxx> Signed-off-by: Vegard Nossum <vegard.nossum@xxxxxxxxxx> --- Documentation/process/security-bugs.rst | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/Documentation/process/security-bugs.rst b/Documentation/process/security-bugs.rst index 2dd6569a7abb..61742dcfea50 100644 --- a/Documentation/process/security-bugs.rst +++ b/Documentation/process/security-bugs.rst @@ -18,7 +18,26 @@ vulnerability. Note that the main interest of the kernel security list is in getting bugs fixed and getting patches reviewed, tested, and merged; CVE assignment, disclosure to distributions, and public disclosure happen on -different lists with different people. +different lists with different people, as described below. + +Here is a quick overview of the various lists: + + =============================== ===== =================== =============== + List address Open? Purpose Members + =============================== ===== =================== =============== + security@xxxxxxxxxx no | Reporting Trusted kernel + | Patch development developers + ------------------------------- ----- ------------------- --------------- + linux-distros@xxxxxxxxxxxxxxx no | Coordination Distribution + | CVE assignment representatives + | Backporting + | Testing + ------------------------------- ----- ------------------- --------------- + oss-security@xxxxxxxxxxxxxxxxxx yes | Disclosure General public + =============================== ===== =================== =============== + +The following sections give a step-by-step guide to reporting and +disclosure. Contacting the security list ---------------------------- -- 2.40.0.rc1.2.gd15644fe02