|
|
Message-ID: <CAA1XrhMqUXWTn1NTZafvS4NnisqMJPom0VMiSGVBLyu7OaGQvw@mail.gmail.com> Date: Wed, 19 Aug 2026 00:09:20 +0200 From: Tristan <TristanInSec@...il.com> To: Collin Funk <collin.funk1@...il.com> Cc: oss-security@...ts.openwall.com, Simon Josefsson <simon@...efsson.org> Subject: Re: GNU Inetutils talkd buffer overflow with long DNS names. Hi Collin, Thank you very much for the smooth and professional collaboration on this issue, and glad to see CVE-2026-19720 assigned. Best regards, Tristan Madani *// Talence Security* Le sam. 15 août 2026 à 05:16, Collin Funk <collin.funk1@...il.com> a écrit : > Collin Funk <collin.funk1@...il.com> writes: > > > ## Timeline > > > > 2026-07-02: Report sent to inetutils-security@....org > > 2026-07-02: I (Collin Funk) acknowledged the report and asked a few > > questions regarding the issue. > > 2026-07-04: Tristan answered those questions. > > 2026-07-06: I reproduced the issue updated Tristan with a planned > > timeline for the fix and CVE assignment. > > 2026-07-08: Tristan agreed to the timeline and offered to review the > > patch. > > 2026-07-11: I wrote the patch and sent it to Tristan. > > 2026-07-15: Tristan confirmed the patch worked as expected. > > 2026-07-16: Private mail to distros mailing list along with the > patch. > > 2026-07-24: I wrote this report and sent it to oss-security. > > > > Note that I also requested a CVE when emailing distros, but haven't > > heard back. I'll probably reach out privately to a CNA in a bit, and > > will update here once one is assigned. > > Red Hat assigned CVE-2026-19720 to this issue yesterday, 2028-08-13. > > Collin >
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.