On Sun, Jul 26, 2026 at 09:53:05PM +0400, Marc-André Lureau wrote:
> Hi
> 
> On Sun, Jul 26, 2026 at 9:14 PM Michael Tokarev <[email protected]> wrote:
> >
> > On 7/26/26 20:07, Marc-André Lureau wrote:
> > ...>> Unfortunately this (additional) fix does not mention the
> > >> previous fix, so there's some confusion about which commit
> > >> actually fixed this issue.  It looks like the first fix was
> > >> incomplete and this additional fix were needed.
> > >
> > > That's correct, we reused the same CVE
> > >
> > > Daniel P. Berrangé said on the issue:
> > > We didn't release master yet. As long as we also didn't release any
> > > stable branches that claimed to fix it, we could re-use it IMHO.
> >
> > Heh.  This is exactly what actually happened - there were
> > 2 stable releases on Jun-25 (v10.0.11 and v11.0.2) which
> > contained the first half.  Now there are 2 more stable
> > releases from Jul-24 which contains the second half.
> >
> > Unfortunately I haven't noticed this duplicated CVE#,
> > or else I'd add a note to the second half in the stable
> > pick-ups.
> >
> > I know you don't like me rushing things to the stable
> > series, and this is an example why this might be bad.
> > Fortunately this is not a regression, at least.  And
> > usually security fixes come in faster anyway.  Ohwell..
> > I'm sorry to disappoint you further.
> 
> for the record, I do appreciate your work, and I make mistake too :)
> Next time I'll check if a release was made already with the CVE#

Or we just declare a strict "never reuse a CVE once a patch is
merged to master" rule.

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|


Reply via email to