CVE-2026-5917: Escape repo path in gen_proto() - #7347
Conversation
Takes inspiration from 346f28b Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
Welp. Yes, this is true. We are going through responsible disclosure for this bug. Or, we were! I guess this has now been disclosed. And you've assigned yourself a CVE for it. Let's coordinate better in the future, please? |
|
https://access.redhat.com/security/cve/cve-2026-5917 indicates that it was publicly disclosed on Aug. 11th. Since I didn't see a fix ready, I assumed it had blindsided you and tried to get you a fix ASAP. |
|
Thanks - my many apologies: I misunderstood, and it is not you with whom I should be grouchy. I am preparing some patch releases tonight since we had this in the queue, but it was batched with other security fixes. Once that's done, I will figure out what's happened here. |
|
Not a problem. And you're correct: I should have reached out before publishing the PR. I wasn't thinking. I'll do better next time. |
|
Not sure that I agree. It was already public, and you were acting proactively to keep people safe and secure. You were effectively mitigating a zero day (or in fact a -2 day). Thank you for that, and again, apologies for the snap reaction. I was busy with something else and didn't give this the attention that it deserved. My mistake, thank you, and apologies again. |
Takes inspiration from 346f28b
Signed-off-by: Stephen Gallagher sgallagh@redhat.com