On Fri, Jul 31, 2026 at 08:46:13PM +0800, zx l wrote:
Hello BIRD maintainers, I am a security researcher working on open-source routing software security. Previously, I submitted several security issue reports to bird-support@network.cz, including vulnerability analysis, reproduction steps, and technical details related to the BIRD routing daemon. However, I have not received any acknowledgement or feedback so far. I would like to confirm whether these reports have reached the appropriate development/security team, or whether there is another preferred channel for reporting security issues.
Could you please help confirm the appropriate security reporting process and whether the previous reports have been received? Thank you very much for maintaining the BIRD routing project.
Hi Your reports were received, receipt was acknowledged by me (you should get a mail from Fri, 03 Jul 2026 12:07:13). Some of them were reviewed and merged, acknowledgement/credit was noted in appropriate commit messages: https://gitlab.nic.cz/labs/bird/-/commit/0e55258d629c149c479e67c77c572039b02... https://gitlab.nic.cz/labs/bird/-/commit/59f7b7fb6cf2aa0cbe3640db340c2dd37d3... https://gitlab.nic.cz/labs/bird/-/commit/0fa4306fe5c8d9a516c1911c7b38e8f89db... https://gitlab.nic.cz/labs/bird/-/commit/73fb2b345b48641f92f3d9b49b685945d91... Rest we did not reviewed yet. Your reporting process was fine (although i would prefer to also get some info wheter reported bugs are specific to BIRD 3 or apply also to BIRD 2), we were just busy and forgot to comment back when fix were merged. -- Elen sila lumenn' omentielvo Ondrej 'Santiago' Zajicek (email: santiago@crfreenet.org) "To err is human -- to blame it on a computer is even more so."