Bootlin takes the security of its infrastructure, services and software seriously. We welcome reports from customers, security researchers and members of the open-source community who believe they have identified a security vulnerability related to Bootlin.
Reporting a security vulnerability
Please report potential security vulnerabilities to:
security@bootlin.com
This address is monitored by designated members of the Bootlin team responsible for coordinating the handling of security reports.
Please do not use this address for general technical support or non-security-related issues.
What to include in a report
To help us investigate the issue efficiently, please provide as much relevant information as possible, including:
- the affected software, service or system;
- the affected version or configuration, when known;
- a description of the vulnerability and its potential security impact;
- the steps required to reproduce the issue;
- any conditions required to trigger or exploit the vulnerability;
- relevant logs, traces or other diagnostic information;
- proof-of-concept code, when appropriate.
Please avoid including personal data or unrelated confidential information in the report.
Sensitive information
If a vulnerability report contains sensitive or non-public information, it may be encrypted using one of the following GPG public keys:
Encrypted reports should be sent to security@bootlin.com.
What to expect from Bootlin
We acknowledge security vulnerability reports within two business days.
When a report falls within Bootlin’s scope, we:
- assign it a tracking identifier;
- perform an initial assessment of the report;
- identify the affected software, systems or customers, where applicable;
- coordinate investigation and remediation with the relevant parties;
- provide status updates when appropriate.
The time required to investigate and resolve a vulnerability depends on its severity, complexity, affected components and the involvement of customers or upstream open-source projects.
Scope
Bootlin is primarily an engineering services company. Our work frequently involves customer products and upstream open-source projects such as the Linux kernel, U-Boot, Buildroot and the Yocto Project.
A vulnerability reported to Bootlin may therefore concern software or systems for which Bootlin is not the manufacturer, owner or maintainer.
When a reported vulnerability concerns:
- Bootlin-operated infrastructure or services, Bootlin coordinates its investigation and remediation;
- software maintained by Bootlin, Bootlin coordinates the vulnerability handling process as appropriate;
- a customer product or customer-controlled software, Bootlin coordinates with the affected customer in accordance with the applicable project and confidentiality requirements;
- an upstream open-source project, Bootlin may coordinate with the appropriate upstream maintainers, taking into account customer confidentiality and coordinated disclosure requirements.
Reporting a vulnerability to Bootlin does not imply that Bootlin is responsible for the complete product or software stack in which the vulnerability was identified.
Coordinated disclosure
We ask reporters to give Bootlin and other affected parties a reasonable opportunity to investigate and address a vulnerability before making information about it public.
Bootlin coordinates vulnerability disclosure with affected customers, upstream projects and other relevant parties where appropriate.
We ask reporters to avoid:
- publicly disclosing a vulnerability before an appropriate coordinated disclosure has taken place;
- accessing, modifying or deleting data that is not necessary to demonstrate the vulnerability;
- disrupting Bootlin, customer or third-party systems or services;
- attempting to access accounts or systems for which they do not have authorization;
- using social engineering, phishing or physical attacks.
If you believe that disclosure is time-sensitive or that a vulnerability is being actively exploited, please mention this clearly in your initial report.
Good-faith security research
Bootlin appreciates good-faith efforts to identify and responsibly report security vulnerabilities.
Security research must comply with applicable law and must not intentionally compromise the privacy, confidentiality, integrity or availability of Bootlin, customer or third-party systems and data.
This policy does not grant authorization to test customer systems, third-party systems or infrastructure that Bootlin does not own or operate.
Security contact
Email: security@bootlin.com
For machine-readable vulnerability reporting information, see our security.txt file.
