RFC: Extending the Glibc CNA to handle GNU Binutils CVEs
Collin Funk
collin.funk1@gmail.com
Wed Jun 10 14:34:36 GMT 2026
Nick Clifton <nickc@redhat.com> writes:
> Hi Guys,
>
> Over the last decade or so almost all of the Binutils bugs which have
> achieved Common Vulnerability and Exposures [1] status have been
> bogus. In the sense they whilst they are bugs, they are not ones that
> could be exploited by an attacker to compromise a system or a network.
> This is a problem - for me and for other people who maintain the
> binutils package in distributions - because any CVE that gets filed
> has to be carefully examined and potentially will cause a lot of work
> back-porting the fix to all the supported releases.
>
> Recent updates to the SECURITY.txt document should help to reduce the
> number of CVEs that actually have to be fixed by distribution
> maintainers but it would be better if the CVEs were never created in
> the first place.
>
> To this end therefore we are looking into extending the scope of the
> current glibc CVE Numbering Authority [2] so that it will also handle
> Binutils bugs. This should be a relatively process and it would mean
> that the glibc CNA security team can review submitted binutils bug
> reports and actually decide if they really do meet the criteria for
> being assigned a CVE rating. It will also help that the glibc folks
> are familiar with the binutils and what the tools do.
>
> My question to you guys then is:
>
> * Are there any concerns or objections to this idea ?
That sounds like a good idea to me.
I briefly considered suggesting GNU become a CNA after noticing some
bogus CVEs filed in Bison and some mostly inactive GNU projects. I never
ended up doing it since those calmed down, but they were annoying
nonetheless.
Collin
More information about the Binutils
mailing list