LWN: grsecurity 2.1.0 and Kernel Vulnerabilities Jan 10, 2005, 13 :45 UTC (4 Talkback[s]) (6445 reads) (Other stories by Brad Spengler)
"Between December 15th and today, Linus has committed many changes to
the kernel. Between January 2nd and today, Andrew Morton has committed
several changes to the kernel. 3 weeks is a sufficient amount of time
to be able to expect even a reply about a given vulnerability. A patch
for the vulnerability was attached to the mails, and in the PaX team's
mails, a working exploit as well. Private notification of
vulnerabilities is a privilege, and when that privilege is abused by not
responding promptly, it deserves to be revoked..."