Conversation

Say (completely hypothetical!) there was an easy unpriv -> root privesc added by a Google employee to the 5.13 kernel, does the Google VRP pay for an exploit/report/fix even if they don't currently use the kernel (presumably)?
1
23
Replying to
They wouldn't pay for a recent mainline kernel bug. Official rule is that it has to impact Pixels to qualify. In practice, it's broader and they would probably pay a bounty if the kernel bug was in Android common kernel tagged releases shipping on devices but not yet Pixels.
1
2
Replying to and
A new mainline bug would usually only qualify without 1-2 years of delay if it got backported to an LTS. Not clear how long it would need to be in an LTS branch to qualify. I don't think they'd pay out for the LTS branches that aren't really used in production yet either.
1
2
Show replies