Hello,

On Wed, Jul 15, 2026 at 12:48:22PM +0200, Matthias Gerstner wrote:
> 5) CVE Assignments
> ==================
> 
> We approached the upstream SELinux userspace utilities developers and
> suggested to assign CVEs for the two issues discussed above. Upstream
> informed us that they don't take care of CVE assignment themselves,
> however. Since Red Hat developers are also involved with upstream
> development, we are currently waiting for an agreement on who will
> assign CVEs to avoid duplicates.

we got a response from upstream devs by now and as a result assigned
CVEs on our end as follows:

> 3.1) Local File Deletion Attack Vector in rm_rf()

CVE-2026-59676

> 3.2) Process Kill Attack Vector in killall()

CVE-2026-59677

Best Regards

Matthias

-- 
Matthias Gerstner <[email protected]>
Security Engineer
https://www.suse.com/security
GPG Key ID: 0x14C405C971923553
 
SUSE Software Solutions Germany GmbH
HRB 36809, AG Nürnberg
Geschäftsführer: Jochen Jaser, Andrew McDonald

Attachment: signature.asc
Description: PGP signature

Reply via email to