Streamlining CVE assignment for glibc

Florian Weimer fweimer@redhat.com
Fri Oct 2 20:08:00 GMT 2015


On 10/02/2015 08:29 PM, Roland McGrath wrote:
> Just make sure it explains everything about CVEs and our processes related
> to them that glibc hackers might need to know.

If you don't care for CVE for other reasons, you can ignore it.

As far as the security process is concerned, *please* mark security bugs
as security+ in Bugzilla.  Similarly, when reviewing patches and you
think you are looking at a bug fix which addresses a security
vulnerability without being recognized as such, please speak up.

A significant fraction of important security bugs started as
non-security bugs and were recognized as security-relevant only after
fixing them.  Which is both a good (we are fixing relevant bugs) and bad
(downstreams will miss opportunities to bundle security fixes with other
changes).

Florian



More information about the Libc-alpha mailing list