Security Audit

Linux Kernel Vulnerability Remediation and Reporting Security Review

The Linux Kernel Vulnerability Reporting and Remediation Review is complete! It covered the Linux Kernel’s practices and policies around how security vulnerabilities are reported to the kernel team, how those reports are processed and addressed, and how those vulnerabilities are disclosed to the public. The Open Source Technology Improvement Fund (OSTIF), working with the team at Atredis Partners and a coalition of interested parties from the Kernel team including the Linux Foundation, Google Android, Google Cloud, and Red Hat worked together to map out the current system in place, and look for opportunities to improve upon that system to potentially improve the overall security of the kernel and to resolve potential problems with downstream projects like Android, Debian, Red Hat Enterprise Linux, Fedora, Ubuntu, CentOS, Arch, OpenSuse, and so many more. Reading the full report is highly recommended. It is available for free at: https://ostif.org/a-review-of-the-linux-kernels-vulnerability-reporting-and-remediation/ Thank you to Linux Foundation for sponsoring this critical work.

Current Balance

$5

$66.01K raised of $66K goal

100% funded

2 supporters

Funding allocation

other

Donated$5
Spent$66K

Goal: $66K

ostif

Donated$0
Spent$0

Goal: $0

Sponsors

Linux Foundation
Lossos ..

Recent donations

Lossos ..
$5
Linux Foundation
$66K