• Pl chevron_right

      Michael Catanzaro: How to Request a CVE

      news.movim.eu / PlanetGnome • 15:00 • 1 minute

    As previously announced, I have discontinued my tracking of GNOME security issues. Nobody else has volunteered to continue that work, so it has concluded (except for issues reported during September 2026, which I will keep an eye on until the end of this month).

    Maintainers, I encourage you to request your own CVEs by writing to Red Hat Product Security. Red Hat is an ideal CNA (CVE Numbering Authority) to use for GNOME CVEs because you will receive timely responses. Ignore Red Hat’s suggestions to encrypt your mail using GPG, and use the following email template:

    Hi, I request a CVE for:
    
    Summary:
    Requirements to exploit:
    Component affected:
    Version affected: All versions <-- change this if needed
    Patch available: Yes/No
    Version fixed (if any already):
    Upstream coordination: See issue report (below)
    CVSS (optional):
    Impact (optional):
    Embargo: No
    Acknowledgment:
    Steps to reproduce if available: see issue report
    Mitigation if available: <-- it's OK to write "None"
    Original report:

    Request a CVE after making your issue report public. It’s possible to reserve a CVE in advance, but this requires twice as many steps, so I recommend making it public first, then request a CVE second.

    GNOME and Fedora maintainers should feel free to get in touch with me if you have questions.