Demi Marie Obenour <[email protected]> wrote: > On 10/4/26 18:56, Jan Schaumann wrote:
> > I was wondering whether it might make sense to > > establish a disclosure list for cloud computing / > > virtual private server hosting providers. > - Xen Project already has its own predisclosure list. > - KVM (sadly) falls under the Linux kernel security process. > - Cloud Hypervisor and QEMU have their own processes. > - Not sure about Firecracker. I think this somewhat helps make my point: cloud compute providers may use several of those, but not consistently (or at all) receive advanced notifications. Centralizing this (with, agreed, some definitions of who qualifies to be determined) would also make it easier for researchers to responsibly disclose. The linux kernel disclosure path is currently rather suboptimal, with urgent and actionable vulnerabilities easily getting buried under hundreds of non-actionable or non-urgent fixes. Having said that, while I'm sympathetic to Aaron's points (minimize likelihood of possible leaks; providers ought to be able to act quickly), having even a few days to get your ducks in a row before the hype circus kicks off of some social media and company blog post would indeed be nice. -Jan
