@alexanderkjall @jmm hmm…
As such, the kernel security team strongly recommends that as a reporter of a potential security issue you DO NOT contact the “linux-distros” mailing list UNTIL a fix is accepted by the affected code’s maintainers and you have read the distros wiki page above and you fully understand the requirements that contacting “linux-distros” will impose on you and the kernel community.
Well, if it’s too complicated to be a reporter, there is always fulldisclosure@seclists.org. ;)