Publishing security fixes without CVE numbers
Hauke Mehrtens
hauke at hauke-m.de
Wed Jun 10 03:09:24 PDT 2026
Hi,
It takes a long time to get a CVE number assigned for a problem. In the
past using the github advisory worked in ~2 business days, we are
waiting for them over 1 week now. Directly over MITRE never worked for
me, I waited there 2 weeks in the past and did not got an answer.
I think we should publish fixes for security problems without a CVE
number. If someone wants to assign a number to it later anyone can do this.
Currently getting a CVE number delays the fixing of security problems by
days or weeks and also takes effort on our side.
Maybe the people at openwall have an idea:
https://www.openwall.com/lists/oss-security/2026/06/10/1
If this does not improve I suggest to not wait for a CVE number with
publishing fixes and details about a security problem in the future.
Hauke
More information about the openwrt-adm
mailing list