Sync a voice

rdwyer@fastmail.com · all

Re: Reporting CVE as fixed back to authority

Thu Sep 10, 2026 · 01:27 AM EDT

From
Daniel Leidert <daniel.leidert@wgdd.de>
To
debian-security@lists.debian.org

Am Donnerstag, dem 10.09.2026 um 06:35 +0200 schrieb Salvatore
Bonaccorso:
> On Wed, Sep 09, 2026 at 11:50:37AM +0300, Alexandru Mihail wrote:

[..]
> > All users still using the server are using the Debian codebase, or
> > derivatives.
>
> I'm not completely sure if I understand what you are aiming for. In
> Debian itself we track it as
> security-tracker.debian.org/tracker/CVE-2026-68005
>
> I assume you wanted to add a note that in Debian the CVE is referenced
> by bugs.debian.org/1144953 ? Then you can via
> cveform.mitre.org ask to update references and add a reference
> to the Debian bug as well.

My understanding is that the OP states that the Debian package source
is the de-facto "upstream" source for anybody still using this software
and they seek advice on how to add information to the original CVE that
the issue has been fixed.

Regards, Daniel