Report security vulnerabilities¶
Important
Please don’t open a public GitHub issue for security problems.
The easiest way to report a security issue is through GitHub. See Privately reporting a security vulnerability for instructions.
The repository admins will be notified of the issue and will work with you to determine whether the issue qualifies as a security issue and, if so, in which component. We will then handle figuring out a fix, getting a CVE assigned and coordinating the release of the fix.
The Ubuntu Security disclosure and embargo policy contains more information about what you can expect when you contact us, and what we expect from you.