订阅内容

Since joining the Common Vulnerabilities and Exposures (CVE) Program in 2002, Red Hat has been committed to excellence, growth and innovation in product security. Today, we’re pleased to announce that Red Hat is now a CVE Numbering Authority of Last Resort (CNA-LR), a prestigious recognition of our leadership, expertise and continued commitment to industry advancement. This achievement is a testament to Red Hat’s dedication and a significant success for the entire open source software (OSS) community of which we are proud to be a part.

Red Hat’s role as a CNA remains, with the company being responsible for assigning CVE identifiers to vulnerabilities that affect open source software, particularly those that impact Red Hat’s products and associated upstream projects. Since 2022, Red Hat has served as a Root organization in the CVE Program, onboarding and mentoring open source software projects to succeed within the Program. Check out the blog, “Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization” for more details. CNA-LR extends this role further, enabling Red Hat to assign CVE IDs and to publish corresponding CVE records within Red Hat Root’s scope for vulnerabilities NOT covered by another CNA.

For example, if the Red Hat Root determines that a CNA within its hierarchy has refused to assign a CVE for any reason, Red Hat, as a CNA-LR, may assign a CVE for that reported vulnerability at the conclusion of the dispute process. You can find all information in the Red Hat CNA-LR Operational Guide.

For over two decades, Red Hat has actively contributed to the goals and initiatives of the CVE Program. Gaining a CNA-LR designation signifies our unwavering dedication and the trust and recognition we have earned within the program. This milestone reflects our relentless pursuit of excellence, strong collaborations and impactful contributions to industry standards and best practices. Additionally, it reinforces the collective strength of the OSS community, whose collaboration and support have been integral to our success.

What this means for you

Achieving CNA-LR status in the CVE Program provides us with new opportunities to help shape the future of our vulnerability ecosystem. With this elevation, we gain access to:

  • Greater influence: A stronger voice for the open source software community in the CVE Program
  • Stronger collaboration: Enhancing our work with more open source software maintainers and the broader community
  • Continued innovation: A platform to drive cutting-edge advancements and thought leadership

A heartfelt thank you

This achievement would not have been possible without the unwavering dedication of our team, the support of our open source community, and the trust of the CVE Program. We extend our deepest gratitude to everyone who has contributed to our journey and helped us reach this significant milestone. We want to thank our open source software community group, whose ongoing support has played a vital role in this success.

What’s next

As we step into this new chapter, we remain committed to driving progress, fostering innovation, and upholding the highest standards of excellence. Our elevation to CNA-LR is an achievement and a stepping stone toward even more outstanding contributions to the industry and open source software community.

Stay tuned for more updates as we continue our journey of leadership and excellence. Thank you for being part of Red Hat’s success story!


关于作者

Pete Allor is the Director for Red Hat Product Security covering the full Red Hat portfolio. He is active in various industry security forums for incident response reporting and secure development, such as NIST and CISA industry calls for input as well as FIRST (first.org), CVE and ISO / ITU / OASIS standards on security.

He is a former Board of Directors Member of FIRST, the Information Technology ISAC and a member of the Executive Board for the IT Sector Coordinating Council. Allor previously worked for Internet Security Systems, IBM and Honeywell. He is a retired US Army Officer.

Read full bio

Yogesh Mittal is a Product Security Manager at Red Hat, primarily focusing on vulnerability management and incident response. He participates in various industry working groups focused on improving vulnerability coordination and disclosure processes.

Read full bio
UI_Icon-Red_Hat-Close-A-Black-RGB

按频道浏览

automation icon

自动化

有关技术、团队和环境 IT 自动化的最新信息

AI icon

人工智能

平台更新使客户可以在任何地方运行人工智能工作负载

open hybrid cloud icon

开放混合云

了解我们如何利用混合云构建更灵活的未来

security icon

安全防护

有关我们如何跨环境和技术减少风险的最新信息

edge icon

边缘计算

简化边缘运维的平台更新

Infrastructure icon

基础架构

全球领先企业 Linux 平台的最新动态

application development icon

应用领域

我们针对最严峻的应用挑战的解决方案

Original series icon

原创节目

关于企业技术领域的创客和领导者们有趣的故事