[PATCH 2/2] advisories: Reject GLIBC-SA-2026-0008

Florian Weimer fweimer@redhat.com
Thu Apr 30 15:55:23 GMT 2026


* Florian Weimer:

>>>>>> +though an incomplete implementation of the APIs was made pulibc.  To the
>>>>>> +best knowledge of the glibc security team no open-source NIS+ server
>>>>>> +implementations were ever released for use with this API.  Applications
>>>>>> +should not use any of the NIS+ APIs and should move to modern identity
>>>>>> +and access management services.
>>>>>>    CVE-Id: CVE-2026-5358
>>>>>>    Public-Date: 2026-04-10
>>>>>> ---
>>>>>>
>>>>>> Like that?
>>>>>
>>>>> Yes, it's fine with me.  Let's wait a bit what others think.
>>>>>
>>>> LGTM too.
>>>> Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
>>>> 
>>>
>>> Thanks. Pushed. CVE is now marked as rejected with MITRE.
>>
>> The rejection did not stick: <https://www.cve.org/CVERecord?id=CVE-2026-5928>
>>
>> Carlos, would you please take a look?
>
> Looks like the CVE ID was reused here:
>
>   <https://sourceware.org/cgit/glibc/tree/advisories/GLIBC-SA-2026-0010>
>
> I don't see an on-list discussion of this change.

Sorry, I must have taken a wrong turn somewhere, and I confused the CVE
ID numbers.

All looks good to me now.

Thanks,
Florian



More information about the Libc-alpha mailing list