Skip to content

Security: Putpocket/IdleScope

SECURITY.md

Security Policy

Supported version

Security fixes are provided for the latest release on the main branch.

Reporting a vulnerability

Please use GitHub private vulnerability reporting. Do not publish exploit details, unsafe device targets, host identifiers, or transaction journals in a public issue before a fix is available.

Treat the following as security-sensitive:

  • any write to a device classified PROTECTED, CAUTION, or UNKNOWN;
  • any mutation before durable APPLY_INTENT or RESTORE_INTENT;
  • bypass of authorization, transaction revision/phase, global lock, or fresh Safety validation;
  • binding a driver when PCI identity or current ownership is ambiguous;
  • a path that writes outside the trusted PCI sysfs controls;
  • corrupt or unsupported journals that do not block active work.

IdleScope supports only explicit SAFE-only DRIVER_DETACH. Do not test a report on production storage, management networking, VFIO/running-VM devices, integrated platform devices, or any target whose dependencies are uncertain.

Include the IdleScope version, Linux distribution and kernel, command used, redacted transaction phase/history, and whether any device-state write could have occurred. Never attach secrets or an unredacted host inventory.

There aren't any published security advisories