cloud computing provider disclosures
oss-security post proposes a disclosure list for cloud and VPS providers outside distros@.
Jan Schaumann asked the oss-security list whether a dedicated disclosure list should exist for cloud computing and virtual private server hosts. He notes that providers which do not ship their own OS or Linux distribution may not qualify for the distros@ list. The post argues that some vulnerabilities still directly and significantly affect cloud environments. No specific flaw, CVE, vendor, or incident is disclosed.
- Proposal posted to oss-security on 4 October 2026 by Jan Schaumann.
- Suggests a disclosure list for cloud and VPS hosting providers.
- Notes many providers ship no own OS and may not qualify for distros@.
- Argues some flaws significantly affect cloud computing even without a vendor distro.
Posted by Jan Schaumann on Oct 04 Hello, I was wondering whether it might make sense to establish a disclosure list for cloud computing / virtual private server hosting providers. The reason that I think this might make sense is that not every cloud computing provider necessarily offers their own OS / Linux distribution, and thus may not be qualified for membership on distros@. At the same time there are vulnerabilities that directly and significantly impact cloud computing...
This source does not provide full text. Read it at seclists.org.