Introduction
SUSE values open collaboration and trust. This Coordinated Vulnerability Disclosure (“CVD”) policy supports SUSE in handling Vulnerability Disclosure in a consistent and constructive way, which contributes to customer and community trust in SUSE.
Purpose
SUSE practises CVD for vulnerabilities in its products and in its own infrastructure.
Scope
This policy applies to all SUSE products and services and the components that make them up. Reports concerning vulnerabilities in SUSE infrastructure are also in scope. Where needed, SUSE will assist in coordinating disclosure with the relevant upstream open source communities.
How to report a vulnerability
Please use whichever of the following channels is appropriate:
- Product vulnerabilities: psirt@suse.com
- SUSE infrastructure vulnerabilities: cybersecurity@suse.com
- Web form (accepts anonymous reports): CRA Form
We recommend OpenPGP encrypted and signed email. Our public keys and their fingerprints are published at https://www.suse.com/support/security/contact/. English is our preferred reporting language. You may also report indirectly, and anonymously if you request it, through a CSIRT designated as national coordinator for coordinated vulnerability disclosure.
To enable SUSE to assess and address the issue in a timely manner, reports must include the following information, where known:
- the affected product and version;
- the environment in which the issue was found;
- the steps to reproduce it;
- how an attacker could exploit it; and
- the immediate impact of exploitation.
Anonymous reports
You may submit a report anonymously using the web form. Anonymous reports can only be processed to a limited extent, or possibly not at all, because we cannot put technical or content questions to you.
What SUSE commits to
- We aim to provide a non-automated response within five working days of receiving your initial report or any substantive update to it. We aim to provide detailed feedback within ten working days: either confirmation or rejection of the reported vulnerability, meaningful questions to us understanding it, or an explanation of why our analysis is taking longer together with a commitment to update you within a further ten working days.
- Your report is treated as confidential to the extent permitted by law, other than information required for public disclosure of the vulnerability.
- We will process the personal data you provide in accordance with applicable personal data protection legislation and SUSE privacy notice. Unless required by applicable law, we will not disclose your personal information to third parties without your consent.
- We will not require you to sign a non-disclosure agreement.
- We will not pursue criminal charges against you where you have complied with this policy. This protection does not apply if there is evidence of malicious intent or if you attempt to exploit a vulnerability for personal gain.
- We remain available as a point of contact for a trusted exchange throughout the process.
- On request, we will credit you on our acknowledgements page once the process is complete.
What SUSE considers a valid vulnerability
- It must affect a SUSE product or SUSE infrastructure.
- It should relate to information that is not publicly known.
- A report consisting only of automated tool or scan output, without supporting analysis, may not qualify.
How SUSE expects reporters to behave
- Do not abuse the vulnerability or cause damage beyond what is necessary to demonstrate it.
- Do not attack SUSE systems, including by social engineering, spam, denial of service or brute force.
- Do not manipulate, compromise or modify third-party systems or data.
- Do not offer tools for exploiting the vulnerability to third parties.
Reports from reporters who do not comply are still handled as far as possible, but non-compliance may mean no acknowledgement. We are committed to processing all reports professionally and in a timely manner. We expect respectful communication on all sides, and enquiries about the status of a report are welcome. SUSE does not operate a bug bounty programme.
The provisions herein do not establish any third-party rights, nor do they constitute permission to perform security testing on SUSE infrastructure outside the explicit scope of this policy.
Embargoes and disclosure timing
Where a fix is not yet available, we will agree a coordinated release date with you and any other stakeholders, and details are shared only with those who need to know until that date. We prefer short embargo periods and will usually suggest 14 to 30 days initially. Validated and verified vulnerabilities are publicly disclosed within 90 days. That period may be extended once by a further 90 days where there is valid justification for a delay in fixing the vulnerability, in close consultation with SUSE’s corresponding national CSIRT. For issues reported to us from external sources we adhere to the conditions stated in the report. Where we have separately agreed a longer period, or a longer period is required by law or by a CSIRT coordinating disclosure, that period applies. If an embargo is broken by premature publication by any party, SUSE may publish immediately any information it is otherwise free to publish.
Regulatory reporting is not public disclosure
SUSE is subject to statutory reporting obligations, including under the EU Cyber Resilience Act, Regulation (EU) 2024/2847. Where those obligations are engaged, SUSE will notify the competent authorities, including its corresponding national CSIRT and ENISA via the Single Reporting Platform, within the applicable statutory deadlines. Such a notification is made in confidence to public authorities. It is not a public disclosure and it is not a breach of any embargo or confidentiality undertaking. SUSE will identify sensitive information as such and, where appropriate, request that onward dissemination be restricted or delayed on cybersecurity grounds. SUSE will notify its corresponding national CSIRT without undue delay of actively exploited vulnerabilities and severe incidents, in accordance with article 14 of the EU Cyber Resilience Act, Regulation (EU) 2024/2847, affecting its products or its infrastructure, and will keep that CSIRT informed of new information, mitigation measures and their schedules.
Publication of fixed vulnerabilities
Once a SUSE product security update is available, or a workaround documented via a security bulletin/TID webpage, SUSE publishes a security advisory describing the vulnerability, the affected products, the impact, the severity and the action users should take. Advisories are published at https://www.suse.com/security/cve/ and, where SUSE requests it in consultation with its corresponding national CSIRT or ENISA, at least on the European Vulnerability Database maintained by ENISA.
Public disclosure of SUSE infrastructure vulnerabilities is subject to case-by-case decisions.
Reporters who wish to publish their own research are required to coordinate with SUSE and are bound to the same disclosure timelines.
When the process ends
The CVD process ends where:
- the report is unfounded;
- the vulnerability has been fixed or mitigated and publicly disclosed;
- the reporter has not responded to technical or content questions for at least 30 days; or
- in consultation with the corresponding national CSIRT, it can no longer be assumed that the vulnerability will be fixed. The unresolved risk remains actively managed internally through our formal exception and risk acceptance process.
We tell the reporter when the process is complete, unless the report was anonymous.
Related information
- SUSE security contacts page: https://www.suse.com/support/security/contact/
- security.txt: https://www.suse.com/.well-known/security.txt
- Privacy notice: https://www.suse.com/company/legal/
- Security advisories: https://www.suse.com/security/cve/
- Acknowledgements page: https://www.suse.com/support/security/contact/ section Acknowledgement / What to expect
Open-source software steward
SUSE provides sustained support to the development and viability of a number of free and open-source software projects. For those projects, SUSE maintains a documented cybersecurity policy in accordance with Article 24 of Regulation (EU) 2024/2847 (Cyber Resilience Act), available to market surveillance authorities on reasoned request. Security vulnerabilities affecting SUSE-supported open-source projects may be reported through psirt@suse.com. SUSE will handle the report or coordinate it with the appropriate project maintainers. Where applicable reporting obligations are triggered, SUSE notifies the competent authorities in accordance with the CRA.
Policy review
SUSE Product Security owns this policy and maintains operational procedures for its execution. This policy will be reviewed annually.