@thesamesam@social.treehouse.systems
Post #2040176
2026-05-04 13:15 UTC
Why are Xen security issues allowed to retain their security marking in commit messages, like in https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.3 ?
Replies (1)
-
@alwayscurious@infosec.exchange 2026-05-08 18:11
@thesamesam@social.treehouse.systems The Xen-related code in Linux is maintained by the Xen Project. Xen has a completely separate process for handling vulnerabilities, and also keeps vulnerabilities under embargo until patches are available. Therefore, pointing out the security marking in the commit message is safe and logical.