We encourage responsible disclosure of security vulnerabilities. If you find something suspicious, we encourage and appreciate your report.
The preferred way to report a vulnerability is to use the "Report a vulnerability" button under the Security tab of the OpenZFS GitHub repository. This creates a private communication channel between you and the maintainers, allowing us to review the report confidentially and respond as quickly as possible.
Please include, if possible:
- A clear description of the issue
- Steps to reproduce the problem
- Affected versions or branches
- Any proof of concept, logs, or screenshots
- Your assessment of the potential impact
- We will review security reports as soon as practical.
- We may ask follow-up questions to better understand the issue.
- Please allow time for investigation and coordination before public disclosure.
- If the issue is confirmed, we will work on a fix and release a security update as needed for supported OpenZFS versions.