A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 15, 2024 6:04 UTC (Thu) by pbonzini (subscriber, #60935)In reply to: A turning point for CVE numbers by sashal
Parent article: A turning point for CVE numbers
I don't think this proves that having a CVE was "necessary to include the bug in older releases". The security impact was missed back in 2022; it's been assessed only now, and this process included filing a CVE. Apart from the affected RHEL releases there are likely millions of devices that have the issue.
But yeah, I can see that it's a nuisance from the upstream point of view and I agree that assigning the CVEs proactively can be an improvement.
