Typically there’s a period of responsible disclosure to give the software maintainer an opportunity to fix it before it’s widely announced. After that period is up or the fix has been released the vulnerability discoverer is able to announce it and take credit for finding it.
Typically there’s a period of responsible disclosure to give the software maintainer an opportunity to fix it before it’s widely announced. After that period is up or the fix has been released the vulnerability discoverer is able to announce it and take credit for finding it.
deleted by creator
https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so#disclosure-timeline
Qualys and Red Hat are pretty big names, so they’d be likely to follow the typical process.