Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID:
 <SA1PR21MB6227986B7A6DD5934CCE949AA5832@SA1PR21MB6227.namprd21.prod.outlook.com>
Date: Tue, 22 Sep 2026 15:11:54 +0000
From: Bas Alberts <anticomputer@...hub.com>
To: Tomas Hoger <thoger@...hat.com>, Sean Whitton <spwhitton@...hitton.name>
CC: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>, Eli
 Zaretskii <eliz@....org>, Michael Albinus <michael.albinus@....de>, Stefan
 Monnier <monnier@....umontreal.ca>, João Távora
	<joaotavora@...il.com>
Subject: Re: Emacs arbitrary code execution:
 incomplete fix for CVE-2024-53920

> Is GitHub going to assign a CVE here?  I think GitHub assignment would
> be ok per this part of the GitHub CNA scope definition:
> "vulnerabilities affecting open source projects discovered by security
> researchers at GitHub or Microsoft not covered by another CNA’s scope."
>
> If GitHub is not doing assignment, Red Hat can provide it instead.

If Red Hat could provide the CVE in line with the previous finding of this report
batch (CVE-2026-79992) that would be greatly appreciated.

Thanks,
Bas


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.