On 10/4/26 18:56, Jan Schaumann wrote:
> Hello,
> 
> I was wondering whether it might make sense to
> establish a disclosure list for cloud computing /
> virtual private server hosting providers.
> 
> The reason that I think this might make sense is that
> not every cloud computing provider necessarily offers
> their own OS / Linux distribution, and thus may not be
> qualified for membership on distros@.
> 
> At the same time there are vulnerabilities that
> directly and significantly impact cloud computing
> providers such that the internet would benefit from
> them being able to mitigate prior to disclosure on
> e.g., oss-security@.
> 
> An obvious example might be disclosure of VM escapes,
> which disproportionally impacts such service
> providers.
> 
> Another option might be to grant cloud computing
> providers membership on distros@ even if they do not
> offer their own custom Linux distribution.
> 
> What do people think?
> 
> -Jan

- Xen Project already has its own predisclosure list.
- KVM (sadly) falls under the Linux kernel security process.
- Cloud Hypervisor and QEMU have their own processes.
- Not sure about Firecracker.

Not sure if a centralized one makes sense, unless there
are individual components used by many providers that
don't fall into one of the above categories.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to