oss-sec mailing list archives

Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2


From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Tue, 28 Apr 2026 16:33:06 -0700

On 4/28/26 15:03, MOHAMED AZIZ RAHMOUNI wrote:
I am following a 90-day responsible disclosure policy. I intend to publish details publicly on 2026-07-27 unless a patch is available sooner, at which point I will coordinate the disclosure timeline with you.

No, you cc'ed oss-security, a public mailing list with public archives:
  https://www.openwall.com/lists/oss-security/2026/04/28/20
so you made uncoordinated public disclosure (aka "dropped 0-day") today.

--
        -Alan Coopersmith-                 alan.coopersmith () oracle com
         Oracle Solaris Engineering - https://blogs.oracle.com/solaris


Current thread: