File: security.rst

package info (click to toggle)
u-boot 2025.01-3
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 330,740 kB
  • sloc: ansic: 2,627,855; python: 60,773; sh: 41,641; asm: 21,854; makefile: 15,048; perl: 12,447; cs: 6,763; cpp: 1,868; yacc: 1,100; lex: 747; awk: 57; tcl: 32; sed: 24
file content (32 lines) | stat: -rw-r--r-- 1,158 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
.. SPDX-License-Identifier: GPL-2.0+:

Handling of security vulnerabilities
====================================

The U-Boot project takes security very seriously.  As such, we'd like to know
when a security bug is found so that it can be fixed and disclosed as quickly
as possible.

Contact
-------

The preferred initial point of contact is to send email to
`u-boot@lists.denx.de` and use `scripts/get_maintainers.pl` to also include any
relevant custodians. In addition, Tom Rini should be contacted at
`trini@konsulko.com`.

CVE assignment
--------------

The U-Boot project cannot directly assign CVEs, nor do we require them for
reports or fixes, as this can needlessly complicate the process and may delay
the bug handling. If a reporter wishes to have a CVE identifier assigned ahead
of public disclosure, they will need to coordinate this on their own.  When
such a CVE identifier is known before a patch is provided, it is desirable to
mention it in the commit message if the reporter agrees.

Non-disclosure agreements
-------------------------

The U-Boot project is not a formal body and therefore unable to enter any
non-disclosure agreements.