From nobody Sat Jul 25 19:29:10 2026 Received: from mail-ed2-f9.google.com (mail-ed2-f9.google.com [74.125.228.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D58A41EFFA1 for ; Tue, 14 Jul 2026 10:46:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=pass smtp.client-ip=74.125.228.73 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784026013; cv=pass; b=RqXUYZGNEywQazSxyhEf/B4Ud7ZMSS15u9d56+34tWguE8s/Z3Omr7RpG6QZ8tauxmE6aE9+1ulKWGIetrCxE0NfeyXEbhHhYzPHB5tak86PxJv2wqrhgkcXxHEr6WPyDd3vCK+tWzaXumQREaYUkaqa/Dowz0yBULo4jbdr0Y0= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784026013; c=relaxed/simple; bh=mdhuYALIRH2WZ6nP3C1YoFgq/rUqlzRofryifcryUEA=; h=MIME-Version:From:Date:Message-ID:Subject:To:Content-Type; b=caz1EfLxLBueEajoy9zQ6torfxfM4U89307Q38fzpJZNgMu6LTil63+puRskW5l95D5lza/B0Hi1rNYNVrX6WbYaXh9pCI88cu33HQXTnXaexWDrPSKQ1GdsvX59bvt9YmgBBZtftWvWZ69Dd/lb9ePOv7Rm0J8yQo4j7f60viM= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dd/P4BHQ; arc=pass smtp.client-ip=74.125.228.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dd/P4BHQ" Received: by mail-ed2-f9.google.com with SMTP id 4fb4d7f45d1cf-69c290c7676so369714a12.0 for ; Tue, 14 Jul 2026 03:46:51 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1784026010; cv=none; d=google.com; s=arc-20260327; b=E5hFajITDnIoMZNbEqW+U5Ws7rxC3lJ6BN/NH0H8giB2tMHf9jURaP0RkRLYnJWoNS ozMr6f/f08weHXktjORMMFsxkP/cOIlJ/siN6iuRkRz+yQxNh/LPtEI0CLVsulyHVxdf Ork7uDk6zht7xIQVz2EFHqybWAjQIZjIuv/sdK529kFrKD/M8XHY5dGptDbNDLGtkcxa CRLRKimnd3nbD7T0J1dXazoFFGF5Ko8SvJDt0PReiBltHSCMBBMiVBFpW2rI272R/hfK ysI6NqVXUopRyxjxp9LqtKH4xmF/Dg9iKM2/6Je0HXhpn9IdBtC8mfraHhqmQFyNIG4w X2Cw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=JMiiLaWZHxi8D3wylL9KT3c3GiQ8G9+5YvO4TUJ2I6I=; fh=PsSyJkPopLzqPYfb7NosT6SOXAuqgiMHb+SO3BM8Nsk=; b=F61lwxLFnWZj4YZtR00IzyfpQMC24mttiIueorFLsr+yuucsytIDAgRSLYQOEu3BC+ nMfXV45C0Sl5ufdr8vK1/8jqQl35g4B0H5nlE/UoxAvPDaaEGBeOYtzEDza0/neDa3L5 6NB+qYkUzYPWouqzFEBFcIVgczyrzCArdYL7QxxDfM/ttXI5gT4AK0GLiS1NU00DIA3n lwoSCaaMghEFP7niCF7bMGVH8FANHLqs8uSDMPpIx3dpHhKXrEpb0H2G98ZgGRiyzCYE S9pEkX5E5yNOyQHETvaGxEdau2YRuRdnk1s1hNBmzzg/NODANe+1VPrwr3v5g/tdcDBy cX1A==; darn=vger.kernel.org ARC-Authentication-Results: i=1; mx.google.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784026010; x=1784630810; darn=vger.kernel.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JMiiLaWZHxi8D3wylL9KT3c3GiQ8G9+5YvO4TUJ2I6I=; b=dd/P4BHQt9u+ks9zPpuradac5t26s9gEADFvZjBrx/XuyXVM/zO00kNHWRXXNVTwm6 vre/BTAA1qTbRcZcFUB0L+gy1jKirUQaJwasX5FrHOu9YL3OaKnQVK8uZBoeXl8rlRz+ xsrQAyCaubspEp+HDG/+yziLeVhFB/vMAPANgG1JOGBTyv34OZHwO5pglA7+Hjc126nB g1gnwaCrYQO6scnkB2/Sbh6oOa/KR/EGIG/XFPP5Fws++Au1yxJhTkeet+1huPHZcMZR ZaWGIf2eo0QC8bMji4EKZh+9Hv7qptymoDROFVgdHsTICVR9k+/J8AOVINE+/h8Myn1t Wz9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784026010; x=1784630810; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JMiiLaWZHxi8D3wylL9KT3c3GiQ8G9+5YvO4TUJ2I6I=; b=IWR7V5//CVdZ9zjNjfFkLOIHs+i2rKiY5tBF/8UStHkxRVNVKbEeouMK61C59uvzi7 FyIu8AEA+YuN36tipJUrQcpdCgaRHUy9DkftdDt0souoslMJJSmM+XuHovzTXmLiDMSh oeHRyJbvcqKg5St3ppDAxKUcWrFa7TRxHeAnfUOOS8hc6gZE/wKlLy3gSfSTGrQFMFHJ x+NGpMucd8dG1MEy9yFKiv6XM7VyC89cqb9pnHg7xV2qVYbyjSozzOfQ9OD2PRDuVGiP Sp1iF8fq5XgB4vkdmrB7r8JbI5oVpznRhupXpM6+bsYkGETE6WjadOQD0+pVwN1NwRwe NyZQ== X-Gm-Message-State: AOJu0YxuctfCn0t6OF1L0SgP3eRUSpPSBWb+m4RgGugcDhGelVsXdpIW C2oNOCgCLSqvGi6zY0rzTWPIHbyeRiRXeQxpKQZPbEpMLoaP2njGkkzn6cV46MDhOj5e48Uh5OI 578euUEnFYpLFMmPt+H3R4Q8cy1vB11JiEuH1jGc0Mw== X-Gm-Gg: AfdE7clWC1gAvP2qdOrbttQF2yb/APwdaXGiNk22YVUyYpysQLByXCZuhgtelTGjyv9 JXMgGe5VXBRl/ghDmqn4sqHyGGbPrFLNRo3u/Ncw3Br1q2cTH30840LJnQG+b0SM3MqikTzZ3A9 X2lHrVLXXsmQLftBMPunhZYPClLEKhK/zzoWpjj3c/gUnKwFXwtjPe4pTmIXMeZ+mTw7DcpH1lj odvDC6NTRDYBGzTV/O4Xv4D+UrxZGXuRAxrKRXwkj8xQqcOjKgFKbEiZodLrzyR6rX8iFo4uO84 YsV4x2wwwQrVBsFDt7ZgwRIuqPYv X-Received: by 2002:a17:907:9d19:b0:c16:6f41:8bf1 with SMTP id a640c23a62f3a-c166f419610mr27149466b.3.1784026009930; Tue, 14 Jul 2026 03:46:49 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 From: Spuntik Date: Tue, 14 Jul 2026 12:46:41 +0200 X-Gm-Features: AUfX_mx5vPcUH0EOzBNgZP-CQqRYyoiVx-IqmkUsFGa1ytLB1cXPCZgfj6egJgw Message-ID: Subject: [PATCH] Add SECURITY.md to redirect GitHub users to official security channels To: linux-kernel@vger.kernel.org, workflows@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From 9b140a7e28c8480ab51bc5441c4d40fa5e5a4e90 Mon Sep 17 00:00:00 2001 From: spuntik1205 Date: Tue, 14 Jul 2026 12:22:32 +0200 Subject: [PATCH] Add SECURITY.md to redirect GitHub users to official security channels GitHub natively supports a `SECURITY.md` file in the root of the repository. When this file is present, GitHub automatically creates a "Security" tab for the repo and displays a prominent link to this policy whenever a user attempts to open a new issue. Since the Linux kernel mirror on GitHub receives a lot of traffic from users who may not be familiar with the kernel's mailing-list workflow, they might incorrectly attempt to report security vulnerabilities through public GitHub channels. This PR adds a standard `SECURITY.md` file that: 1. Explicitly asks users not to report vulnerabilities on GitHub. 2. Directs them to the official `security@kernel.org` mailing list. 3. Links directly to the official `security-bugs.rst` documentation on kernel.org for proper reporting procedures. While I understand the kernel does not use GitHub for development, adding this file will help intercept confused GitHub users and redirect them to the proper kernel security workflows. --- SECURITY.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000000..80b0b46279f6 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,19 @@ +# Security Policy + +## Supported Versions + +The Linux kernel maintains several active branches. The mainline kernel, stable kernels, and longterm maintenance (LTS) kernels are currently supported with security updates. + +Please refer to the [active kernel releases](https://www.kernel.org/category/releases.html) on kernel.org to see which versions are currently receiving security updates. + +## Reporting a Vulnerability + +**Please do not report security vulnerabilities through public GitHub issu= es.** + +If you believe you have found a security vulnerability in the Linux kernel, please report it to the Linux kernel security team. + +1. **Email the Security Team:** Send an email to `security@kernel.org`. +2. **Read the Documentation:** For detailed instructions on what to include in your report, acceptable disclosure timelines, and how the kernel team handles security bugs, please read the official [Security Bugs Documentation](https://www.kernel.org/doc/html/latest/admin-guide/secu= rity-bugs.html). +3. **Hardware Vulnerabilities:** If you are reporting a hardware vulnerability that affects the kernel, please refer to the specific guidelines for [Hardware vulnerabilities](https://www.kernel.org/doc/html/latest/process/embargoed-h= ardware-issues.html) and contact the hardware security team at `hardware-security@kernel.org` if appropriate. + +The security team will review your report and work with you and the relevant subsystem maintainers to develop and release a fix. You can typically expect an initial response within a few days. --=20 2.55.0