Hello,
Sorry, I haven't been totally ignoring this, but also, 9P is not something we use in
our product, and not sure anyone else that uses Ganesha actually uses it these days, so
unfortunately, our priority for addressing has been limited.
One problem is there's no "private" way to put it in a backlog that others
could see, or in fact, be visible to those who are not in communication with us but do use
9P.
Frank
-----Original Message-----
From: Teddy Thobane [mailto:theodore.thobane@gmail.com]
Sent: Tuesday, September 22, 2026 1:17 AM
To: devel(a)lists.nfs-ganesha.org
Cc: ffilzlnx(a)mindspring.com; dang1(a)ibm.com
Subject: [NFS-Ganesha-Devel] Security disclosure escalation – NFS-Ganesha
Hi,
I'm trying to establish contact regarding a high-severity security vulnerability in
NFS-Ganesha.
I originally disclosed the issue privately several weeks ago, but haven't received a
response despite follow-ups. Since the initial report, I've developed the issue
further and confirmed that it can be exploited for pre-authentication remote code
execution.
I don't want to disclose technical details publicly. Could a maintainer please contact
me so that we can establish an appropriate private channel for coordinated disclosure?
Thanks,
Teddy
_______________________________________________
Devel mailing list -- devel(a)lists.nfs-ganesha.org To unsubscribe send an email to
devel-leave(a)lists.nfs-ganesha.org