Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <aatlROBDmUY8v4Gv@thunder.hadrons.org>
Date: Sat, 7 Mar 2026 00:37:40 +0100
From: Guillem Jover <guillem@...ian.org>
To: Salvatore Bonaccorso <carnil@...ian.org>
Cc: Solar Designer <solar@...nwall.com>,
	Ron Ben Yizhak <ron.benyizhak@...ebreach.com>,
	Justin Swartz <justin.swartz@...ingedge.co.za>,
	bug-inetutils@....org, oss-security@...ts.openwall.com,
	simon@...efsson.org, auerswal@...x-ag.uni-kl.de
Subject: Re: CVE-2026-28372: Telnetd Vulnerability Report

Hi!

On Sat, 2026-03-07 at 00:17:55 +0100, Salvatore Bonaccorso wrote:
> On Fri, Mar 06, 2026 at 04:39:23PM +0100, Guillem Jover wrote:
> > I'm not part of the Debian Security Team (I just maintain the inetutils
> > package in Debian), but I think they assigned a CVE because there didn't
> > seem to be one coming from upstream. I guess the expectation would be
> > that if there's a new CVE to be assigned that would be handled by
> > upstream, but if it's needed and it's not forthcoming they might assign
> > another one? (Although the easier way forward would be to reuse the
> > existing one, and issue an update for the DSA.)
> 
> I just need to clarify one thing here: The CVE was not assigned by the
> Debian CNA, but as there was no CVE assigned by the issue reported by
> Ron, I requested one from MITRE. There was none assigned in time when
> we released the DSA, and at that point TTBOMK the more general
> issue/root cause indication by Justin Swartz was not known. So the CVE
> request to MITRE was done specifically as for the issue found by Ron.

Right, sorry, as it seems like I forgot about this (where I was even
CCed in later emails mentioning this)!

Thanks,
Guillem

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.