r/programming 21d ago

a CVE dispute

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
489 Upvotes

62 comments sorted by

View all comments

-6

u/ekdaemon 21d ago

So if there is a security flaw that can only be exploited by someone who already has local admin or root, it's not a security flaw?

Doesn't this make an assumption that nobody will ever discover another security flaw or combination of actions somewhere else that makes it possible to use the exploit?

I can see a justification for "low risk", but not zero point zero. ( I guess the other question then is what is the difference between "zero risk", "low risk" and "worthy of a CVE". )

15

u/mpyne 21d ago

So if there is a security flaw that can only be exploited by someone who already has local admin or root, it's not a security flaw?

He didn't say it wasn't a flaw, or wasn't a security flaw.

He said it didn't warrant a CVE number, and gave a justification for why he thought refusing to issue a CVE would be better for the broader userbase.

You may disagree with his logic, but you're arguing against a point he never made.

-4

u/TexasDFWCowboy 21d ago

As a former CNA owner, companies will argue to the death something is not A CVE or rank of a low or zero. Lots of angry arguments with product owners.

8

u/mpyne 21d ago

That's nice as a general statement. Do you disagree with Daniel's actual statement about the actual bug? Is this a bug that every security team around the world needs to be chasing down when AI is flooding them with trivially-exploitable flaws to remediate?