oss-security debates a dedicated cloud predisclosure list
oss-security participants disagree on a cloud and VPS predisclosure list, weighing size cutoffs, existing processes, exploit risk, and early patch access.
On 4 October 2026, Jan Schaumann asked oss-security whether cloud and VPS hosts that may not qualify for distros@ because they ship no OS of their own should have a dedicated disclosure list, since some flaws still significantly affect cloud environments; no CVE, vendor, or incident was named. On 5 October, Jonathan Wright asked how large a provider must be for predisclosure, citing hosts smaller than AWS, Azure, GCP, and OCP that remain very large. Demi Marie Obenour replied that Xen already has a predisclosure list, KVM follows the Linux kernel security process, QEMU and Cloud Hypervisor have separate processes, and Firecracker's status is unclear, so a centralized list may not help unless shared components fall outside those processes. Aaron Rainbolt opposed the idea, warning that providers must patch immediately because of the zero-day market and that public fixes can be turned into exploits without deeper flaw details. Schaumann later said providers often miss advance notices, that centralizing could aid responsible disclosure, and that the Linux kernel path is suboptimal for urgent bugs, while Jeremy Stanley said early fix access lets operators mitigate alongside advisories and that they have caught pre-release logic and testing gaps; Katie discussed early-access membership and cited fan art as a non-code contribution. The reports do not conflict on facts, but participants disagree on whether the list should exist.
- On 4 October 2026, Jan Schaumann proposed on oss-security a disclosure list for cloud and VPS providers that may not qualify for distros@ because they ship no OS of their own.
- No specific flaw, CVE, vendor, or incident was disclosed in the thread.
- Jonathan Wright asked how large a host must be for predisclosure, noting many providers smaller than AWS, Azure, GCP, and OCP are still very large.
- Demi Marie Obenour said Xen already has a predisclosure list, KVM follows the Linux kernel security process, and QEMU and Cloud Hypervisor have separate processes; Firecracker's status is unclear.
- Aaron Rainbolt opposed the idea, citing the zero-day market and warning that public fixes can quickly be turned into exploits without deeper vulnerability details.
- Schaumann later said providers do not consistently receive advance notices, that centralizing could help responsible disclosure, and that the Linux kernel path is suboptimal for urgent bugs.
- Jeremy Stanley said early fix access lets public cloud operators schedule mitigation with coordinated advisories and that operators have found pre-advisory logic and testing gaps developers missed.
- Katie discussed early-access membership and used fan art as an example of a non-code contribution, with no vulnerability details.
Coverage timelineoldest first · each row is one article
- · 4d agocloud computing provider disclosures
oss-security· 18
oss-security post proposes a disclosure list for cloud and VPS providers outside distros@.
- · 4d agoRe: cloud computing provider disclosures
oss-security· 16
Mailing-list reply asks how large a host must be to join cloud predisclosure.
- · 4d agoRe: cloud computing provider disclosures
oss-security· 22
oss-security reply says Xen, KVM, QEMU, and Cloud Hypervisor already have separate disclosure processes.