oss-sec mailing list archives
Re: Becoming a CVE Naming Authority for your project
From: Jeremy Stanley <fungi () yuggoth org>
Date: Thu, 6 Nov 2025 18:21:10 +0000
On 2025-11-06 12:17:41 -0500 (-0500), Pat Gunn wrote: [...]
Hoping I'm not missing something obvious about this concern that'll make me look the fool, but worried that if nobody speaks up about it this will amount to a corporate capture of things that are best not so owned.
[...]This is part of why projects I work on just apply for assignments straight from MITRE, and wait for a while in some cases. We've intentionally decoupled our advisory publication process from obtaining a CVE so that if it takes them until well after things are public then that's still fine with us. Instead we issue an errata revision for the advisory to add the CVE identifier later once it's finally been assigned.
In the past we've had CVEs assigned to us from interested CNA-wielding companies, and end up with duplicates that then need to be rejected as a result; so while it would be great to be able to prevent that, it sounds like the only way available at the moment is to become our own CNA which is more work than we collectively have time for.
-- Jeremy Stanley
Attachment:
signature.asc
Description:
Current thread:
- Re: Becoming a CVE Naming Authority for your project, (continued)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Pedro Sampaio (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Peter Gutmann (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Matthew Fernandez (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Art Manion (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Pedro Sampaio (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 06)
- Re: Becoming a CVE Naming Authority for your project Peter Gutmann (Nov 07)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Jeremy Stanley (Nov 06)
