Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <D8A3DC3C-8463-4A6A-A3E6-CE3CD7D1BD4D@redhat.com>
Date: Tue, 12 Nov 2024 16:12:18 +0100
From: Clemens Lang <cllang@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2024-36905: Linux kernel: Divide-by-zero on
 shutdown of TCP_SYN_RECV sockets

Hi,

> On 12. Nov 2024, at 15:58, Solar Designer <solar@...nwall.com> wrote:
> 
> So a question for this list/thread may be - where/how may we dispute
> CISA-ADP analysis?  Maybe someone would reply with specific contact info
> for them, and Joel would proceed with that.

I think the source for the CISA-ADP data is at [1]. For this specific CVE, the relevant file would be [2]. Their readme has a section at the bottom, where they encourage feedback:

> We want to hear from you, the IT cybersecurity professional community, about Vulnrichment and ADP! If you see something, please feel free to say something in the Issues, or even better, open a Pull Request with your suggested fix.

I’m aware of at last one prior case where a similar case of (IMHO) overblown CVSS scores was discussed in an issue on this particular GitHub project [3].

Somebody seems to already have opened a ticket for this CVE, too: [4]


[1]: https://github.com/cisagov/vulnrichment
[2]: https://github.com/cisagov/vulnrichment/blob/develop/2024/36xxx/CVE-2024-36905.json
[3]: https://github.com/cisagov/vulnrichment/issues/93
[4]: https://github.com/cisagov/vulnrichment/issues/130


HTH,
Clemens
-- 
Clemens Lang
RHEL Crypto Team
Red Hat

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.