Hi!
Some comments:
A crash, an abort, an assertion failure, or a hang is a **bug**, not a security issue.
So a DoS (Denial of Service) (e.g. by crashing the app from remote) is not a security issue?
**LMDB trusts its own database files by contract.**
A long time Linux did trust filesystems as well, but some people managed to do bad things by providing manipulated filesystem images (e.g. ISOs). So if some deployment scenario would provide an LMDB image, and that image would cause some buffer overflow, resulting in execution of unwanted actions, wouldn't that be a security bug to care for?
In general I think the guidelines are even a bit too technical for the average user.
Kind regards, Ulrich Windl
-----Original Message----- From: Howard Chu hyc@symas.com Sent: Tuesday, August 11, 2026 6:11 PM To: OpenLDAP Technical openldap-technical@OpenLDAP.org Subject: [EXT] Security policy
Since AI-driven "researchers" are submitting more bug reports these days in hopes of adding CVEs to their CVs, we're probably going to need to publish a more formalized security policy on the openldap.org web site. This is an example of what we're starting with. Feedback welcome.
-- -- Howard Chu CTO, Symas Corp. http://www.symas.com Director, Highland Sun http://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/