
oss-sec mailing list archives
issue with stuck Mitre CVE requests
From: Matthias Gerstner <mgerstner () suse de>
Date: Wed, 22 Jan 2025 11:17:54 +0100
Hello list, I am currently experiencing for the second time that a CVE request submitted via the Mitre web form [1] is not receiving a response. A similar topic was already shortly discussed in the past [2]. I requested two CVEs on Jan 13. One got assigned within 24 hours, for the other one I still didn't receive a reply. The same happened to me in April 2024. Back then, after not receiving a reply for over two weeks, the CVE has been assigned by Red Hat instead, since Red Hat developers have been involved in the affected project. In this instance upstream is not a CNA and it is also not closely involved with Red Hat. Replying to the automatic CVE request mail from Mitre does not seem to reach any human being. I don't know of any other way to get attention from Mitre for this request. I wonder what is the best way to recover from such a situation without risking duplicate CVE assignments, or not assigning a CVE at all. I have a hunch that the issue might have to do with filling out the "PGP Key" field in the CVE request form, which I did for the one request that has not been answered, but not for the other, which got assigned right away. Thanks Matthias [1]: https://cveform.mitre.org/ [2]: https://www.openwall.com/lists/oss-security/2024/08/06/3 -- Matthias Gerstner <matthias.gerstner () suse de> Security Engineer https://www.suse.com/security GPG Key ID: 0x14C405C971923553 SUSE Software Solutions Germany GmbH HRB 36809, AG Nürnberg Geschäftsführer: Ivo Totev, Andrew McDonald, Werner Knoblich
Attachment:
signature.asc
Description:
Current thread:
- issue with stuck Mitre CVE requests Matthias Gerstner (Jan 22)
- Re: issue with stuck Mitre CVE requests Greg KH (Jan 22)
- Re: issue with stuck Mitre CVE requests Johannes Segitz (Jan 22)
- Re: issue with stuck Mitre CVE requests Mark Esler (Jan 24)
- Re: issue with stuck Mitre CVE requests Johannes Segitz (Jan 27)
- Re: issue with stuck Mitre CVE requests Pete Allor (Jan 27)
- Re: issue with stuck Mitre CVE requests Johannes Segitz (Jan 22)
- Re: issue with stuck Mitre CVE requests Greg KH (Jan 22)
- Re: issue with stuck Mitre CVE requests Pedro Sampaio (Jan 22)
- Re: issue with stuck Mitre CVE requests Pete Allor (Jan 23)