Re: CVEs issued by the Linux kernel CNA

Posted by Greg KH on Feb 22

That’s the rules from CVE themselves, it’s not unique to the kernel
here. You will run into this more as more open source projects take
over the CVE process for their codebases. curl and python are two
examples of which linux-distros are not allowed to do this for either.

Yes, that is a requirement that all CNAs must now follow.


That is probably NOT ok as per the CVE rules, sorry.

