Comment on Dear Linux Kernel CNA, what have you done?Comments−gtirloni2y> Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identifyShouldn't this strategy lead to the opposite? By being overly cautious they should only assign CVEs for real demonstrable security issues.−martijnvds2yYou can think of it as a "fail-safe" situation.Being cautious here means "it's better to assign a CVE when it's not a vulnerability, than to NOT assign a CVE when it's actually a vulnerability"
Comments
> Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify
Shouldn't this strategy lead to the opposite? By being overly cautious they should only assign CVEs for real demonstrable security issues.
You can think of it as a "fail-safe" situation.
Being cautious here means "it's better to assign a CVE when it's not a vulnerability, than to NOT assign a CVE when it's actually a vulnerability"