oss-sec mailing list archives

Re: Details on this supposed Linux Kernel ksmbd RCE


From: John Helmert III <ajak () gentoo org>
Date: Fri, 23 Dec 2022 10:56:18 -0600

On Fri, Dec 23, 2022 at 09:04:25AM -0500, Sasha Levin wrote:
On Fri, Dec 23, 2022 at 09:17:28AM +0100, Marcus Meissner wrote:
Not sure why they do not like you, but to be very clear anyone else can
requests CVEs for the kernel, (except the blacklisted drivers/staging/ area).

For CVEs assigned (earlier this month) to issues in drivers/staging,
what would be the process to remove the assignment or mark them as
invalid?

Requests for changes to CVEs (like rejections) should go to the
assigning CNA. For MITRE, they want such requests to go through
cveform.mitre.org. For others, you can find contact points on [1].

[1] https://www.cve.org/PartnerInformation/ListofPartners

-- 
Thanks,
Sasha

Attachment: signature.asc
Description:


Current thread: