Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130308045543.GE20032@dhcp-25-225.brq.redhat.com>
Date: Fri, 8 Mar 2013 05:55:44 +0100
From: Petr Matousek <pmatouse@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Requests (maybe): Linux kernel: various info
 leaks, some NULL ptr derefs

On Thu, Mar 07, 2013 at 01:19:05PM +0400, Solar Designer wrote:
> Kurt -
> 
> On Thu, Mar 07, 2013 at 02:13:37AM -0700, Kurt Seifried wrote:
> > Bundling the following into a single CVE:
> [...]
> > Please use CVE-2012-6138 for these issues.
> 
> I think this is wrong.  I would understand if those issues were all in
> the same subsystem at least (or if you assigned per-subsystem CVE IDs
> for these), but this is not the case.  Many distros will fix some, but
> not the others, or not all at the same time.  There's room for a little
> bit of bundling here, but not that much.

In the past we've usually assigned one CVE per issue even for info leak
bugs. Or at least one CVE per subsystem, as Alexander says. I agree with
Alexander that one CVE for about ~20 issues is not right.

-- 
Petr Matousek / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.