oss-sec mailing list archives

Current CVE policy on missing-hardening bugs


From: Florian Weimer <fweimer () redhat com>
Date: Mon, 05 Aug 2019 13:36:54 +0200

What's the current policy on assinging CVE IDs for bugs that are merely
missed hardening opportunities?  One example is lack of full ASLR due to
address space limits (47 or fewer bits instead of the theoretical limit
of 64 bits).

Are they eligible for CVE assignment?  Should we DISPUTE them if we
encounter them?

Thanks,
Florian


Current thread: