Sync a voice

rdwyer@fastmail.com · all

Re: Reporting CVE as fixed back to authority

Thu Sep 10, 2026 · 12:35 AM EDT

From
Salvatore Bonaccorso <carnil@debian.org>
To
debian-security@lists.debian.org

Hi Alexandru,

On Wed, Sep 09, 2026 at 11:50:37AM +0300, Alexandru Mihail wrote:
> Hello, I've recently fixed a CVE reported in mini-httpd, which I solely
> maintain.
>
> CVE-2026-68005
>
> nvd.nist.gov/vuln/detail/cve-2026-68005
>
> This was fixed in: bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144953
>
> The problem is, the official CVE looks at upstream for changes, as it
> should. Upstream is most probably dead, hasn't responded in a long while, I
> am effectively the upstream maintaining this.
>
> How do I/Debian propagate the information that the CVE was fixed ? I don't
> think this will happen automatically, since upstream won't respond to my
> forwarded patches, although I will send them.
>
> All users still using the server are using the Debian codebase, or
> derivatives.

I'm not completely sure if I understand what you are aiming for. In
Debian itself we track it as
security-tracker.debian.org/tracker/CVE-2026-68005

I assume you wanted to add a note that in Debian the CVE is referenced
by bugs.debian.org/1144953 ? Then you can via
cveform.mitre.org ask to update references and add a reference
to the Debian bug as well.

Does this help?

Regards,
Salvatore