Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20260416193451.GA20893@openwall.com>
Date: Thu, 16 Apr 2026 21:34:51 +0200
From: Solar Designer <solar@...nwall.com>
To: yangjincheng1998@...il.com
Cc: oss-security@...ts.openwall.com, alan.coopersmith@...cle.com
Subject: Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory

Hi,

Disclaimer: I'm replying based on limited context, without looking into
the actual issues.

On Thu, Apr 16, 2026 at 12:22:59PM -0700, yangjincheng1998@...il.com wrote:
> Good catch -- sorry for the confusion. The "Duplicate - please ignore"
> titles on #3433 and #3434 are my own housekeeping rename, done on
> 2026-04-11, AFTER the Kvrocks maintainers had already closed both
> issues on 2026-04-09 via a single fix PR. The original bodies were
> the actual vulnerability reports.

What you did is very confusing.  It looks like you created the issues on
2026-04-08, so I don't see why having them fixed a day later would make
them "duplicate" or "submitted in error".  Maybe it was your attempt to
hide the vulnerability reports until proper publication?  If so, I think
that was a bad idea.  I suggest that you restore your original titles
and content of these issues.  The original content is seen in the edits
history anyway, it's just harder to find now.

Thanks,

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.