This is an old revision of the document!
Statistics are grouped by month of the issue being reported to the private list.
| Month | All reports | Embargoed | Average | Median | Min | Max embargo days |
|---|---|---|---|---|---|---|
| 2026-01 | 3 | 3 | 7.42 | 6.81 | 1.28 | 14.15 |
| 2026-02 | 4 | 4 | 11.57 | 12.70 | 6.75 | 14.15 |
| 2026-03 | 15 | 15 | 10.40 | 5.35 | 1.11 | 49.69 |
| 2026-04 | 16 | 16 | 9.84 | 6.06 | 3.60 | 31.98 |
| 2026-05 | 17 | 17 | 6.79 | 6.02 | 0.14 | 17.14 |
| 2026-06 | 14 | 14 | 11.30 | 7.08 | 0.07 | 57.65 |
| 2026-07 | 22 | 22 | 11.24 | 7.47 | 1.16 | 43.40 |
| 2026-08 | 17 | 17 | 7.19 | 5.99 | 1.03 | 14.79 |
| Total | 108 | 108 | 9.49 | 6.90 | 0.07 | 57.65 |
Non-embargoed reports (issue already posted to oss-security before being brought to (linux-)distros, which in 2026 didn't occur yet) are (would be) excluded from the calculation of average, median, and minimum embargo duration above.
For the statistics above, we only use the first embargo duration seen in this table, which is the delay between postings to (linux-)distros and oss-security.
For some reports, there's a second embargo duration - that one is the delay (sometimes negative) between a first public posting elsewhere and the posting to (linux-)distros. Such first public posting often does not fully (or at all) reveal security relevance of the issue/fix, making it not-too-unreasonable to allow a little bit (more) of embargo time on the full detail, especially when that's the issue reporter's and/or the upstream project's preference.
These files were manually created based on review of the e-mail threads and external resources referenced from there. They were processed with this Perl script to produce the tables above. You should be able to reproduce that.