|
|
Log in / Subscribe / Register

The bogus CVE problem

The bogus CVE problem

Posted Sep 22, 2023 17:06 UTC (Fri) by fung1 (guest, #144307)
Parent article: The bogus CVE problem

I mostly run the vulnerability management team for a large ecosystem of popular free/libre open source services. We request CVE assignments as a matter of course when we determine that we're going to issue a security advisory, and use them for the purpose they were intended (tracking). We purposefully do not make up CVSS scores because the heck if I can guess whether this specific problem is critical or benign in your deployment, it all depends on how you're using our software. At least for us, CVSS is entirely pointless.

We also do not bother to dispute CVE assignments others request for bugs in our software, because it's not worth our (limited) time to do so. It's our policy that if someone has requested a CVE for one of our bugs and notified us what number got assigned, then we'll reuse that *if* we issue an advisory (instead of requesting a conflicting CVE). It's been clear for a very long time that since anyone can request and receive a CVE assignment without even talking to the people maintaining the project it's about, the mere existence of a CVE does not imply there's any sort of vulnerability, nor is there any point in wasting time trying to get them rescinded.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds