Re: cloud computing provider disclosures
oss-security reply says Xen, KVM, QEMU, and Cloud Hypervisor already have separate disclosure processes.
Demi Marie Obenour replied on oss-security to a thread about cloud-provider vulnerability predisclosure. She notes the Xen Project already maintains its own predisclosure list, while KVM follows the Linux kernel security process. Cloud Hypervisor and QEMU have separate processes, and Firecracker's status is unclear. She questions whether a centralized list is useful unless shared components fall outside those processes.
- Xen Project already runs its own predisclosure list.
- KVM issues follow the Linux kernel security process.
- QEMU and Cloud Hypervisor use separate disclosure processes.
- A single centralized cloud predisclosure list may not help.
Posted by Demi Marie Obenour on Oct 04 - Xen Project already has its own predisclosure list. - KVM (sadly) falls under the Linux kernel security process. - Cloud Hypervisor and QEMU have their own processes. - Not sure about Firecracker. Not sure if a centralized one makes sense, unless there are individual components used by many providers that don't fall into one of the above categories.
This source does not provide full text. Read it at seclists.org.