RFC: Extending the Glibc CNA to handle GNU Binutils CVEs

Collin Funk collin.funk1@gmail.com
Wed Jun 10 14:34:36 GMT 2026


Nick Clifton <nickc@redhat.com> writes:

> Hi Guys,
>
> Over the last decade or so almost all of the Binutils bugs which have
> achieved Common Vulnerability and Exposures [1] status have been
> bogus.  In the sense they whilst they are bugs, they are not ones that
> could be exploited by an attacker to compromise a system or a network.
> This is a problem - for me and for other people who maintain the
> binutils package in distributions - because any CVE that gets filed
> has to be carefully examined and potentially will cause a lot of work
> back-porting the fix to all the supported releases.
>
> Recent updates to the SECURITY.txt document should help to reduce the
> number of CVEs that actually have to be fixed by distribution
> maintainers but it would be better if the CVEs were never created in
> the first place.
>
> To this end therefore we are looking into extending the scope of the
> current glibc CVE Numbering Authority [2] so that it will also handle
> Binutils bugs.  This should be a relatively process and it would mean
> that the glibc CNA security team can review submitted binutils bug
> reports and actually decide if they really do meet the criteria for
> being assigned a CVE rating.  It will also help that the glibc folks
> are familiar with the binutils and what the tools do.
>
> My question to you guys then is:
>
>   * Are there any concerns or objections to this idea ?

That sounds like a good idea to me.

I briefly considered suggesting GNU become a CNA after noticing some
bogus CVEs filed in Bison and some mostly inactive GNU projects. I never
ended up doing it since those calmed down, but they were annoying
nonetheless.

Collin


More information about the Binutils mailing list