Security fixes are provided for the latest release on the main branch.
Please use GitHub private vulnerability reporting. Do not publish exploit details, unsafe device targets, host identifiers, or transaction journals in a public issue before a fix is available.
Treat the following as security-sensitive:
- any write to a device classified
PROTECTED,CAUTION, orUNKNOWN; - any mutation before durable
APPLY_INTENTorRESTORE_INTENT; - bypass of authorization, transaction revision/phase, global lock, or fresh Safety validation;
- binding a driver when PCI identity or current ownership is ambiguous;
- a path that writes outside the trusted PCI sysfs controls;
- corrupt or unsupported journals that do not block active work.
IdleScope supports only explicit SAFE-only DRIVER_DETACH. Do not test a report on production
storage, management networking, VFIO/running-VM devices, integrated platform devices, or any
target whose dependencies are uncertain.
Include the IdleScope version, Linux distribution and kernel, command used, redacted transaction phase/history, and whether any device-state write could have occurred. Never attach secrets or an unredacted host inventory.