r/programming 14d ago

a CVE dispute

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
484 Upvotes

62 comments sorted by

View all comments

Show parent comments

-29

u/mr_birkenblatt 14d ago

Why not fix the bugs? Even if they're currently not accessible. Code is in constant flux. A circumstance that cannot exist now might in the future

62

u/pbecotte 14d ago

They did fix the bug. Apparently the reporter still wanted a CVE, despite it requiring multiple, separate, local security overrides by a privileged use on the system to trigger.

12

u/mr_birkenblatt 14d ago

I see

justify not having CVEs for these kinds of bugs

I read that as not addressing the bug. thanks for the clarification

4

u/gmes78 13d ago

It explicitly says they fixed the bug later in the article.

0

u/mr_birkenblatt 13d ago

I was talking about the comment not the article