On Fri, Jul 31, 2026 at 08:46:13PM +0800, zx l wrote: > Hello BIRD maintainers, > I am a security researcher working on open-source routing software > security. Previously, I submitted several security issue reports to > [email protected], including vulnerability analysis, reproduction > steps, and technical details related to the BIRD routing daemon. However, I > have not received any acknowledgement or feedback so far. I would like to > confirm whether these reports have reached the appropriate > development/security team, or whether there is another preferred channel > for reporting security issues. > > Could you please help confirm the appropriate security reporting process > and whether the previous reports have been received? Thank you very much > for maintaining the BIRD routing project.
Hi Your reports were received, receipt was acknowledged by me (you should get a mail from Fri, 03 Jul 2026 12:07:13). Some of them were reviewed and merged, acknowledgement/credit was noted in appropriate commit messages: https://gitlab.nic.cz/labs/bird/-/commit/0e55258d629c149c479e67c77c572039b02daff9 https://gitlab.nic.cz/labs/bird/-/commit/59f7b7fb6cf2aa0cbe3640db340c2dd37d36bdca https://gitlab.nic.cz/labs/bird/-/commit/0fa4306fe5c8d9a516c1911c7b38e8f89dbf7b4a https://gitlab.nic.cz/labs/bird/-/commit/73fb2b345b48641f92f3d9b49b685945d91feda5 Rest we did not reviewed yet. Your reporting process was fine (although i would prefer to also get some info wheter reported bugs are specific to BIRD 3 or apply also to BIRD 2), we were just busy and forgot to comment back when fix were merged. -- Elen sila lumenn' omentielvo Ondrej 'Santiago' Zajicek (email: [email protected]) "To err is human -- to blame it on a computer is even more so."
