Glibc becomes a CVE Numbering Authority
The GNU C Library project hasbeen accepted as a CVE Numbering Authority (CNA), meaning that theproject is now in control of the CVE numbers assigned to its code.
As a CNA the glibc security team will be working to improve thequality and response time of security advisories and mitigations.Over the coming months, the glibc security team will define theprocess for the CNA and establish best practices that can also beused by the rest of the GNU Toolchain.
See this article for some background onthis change.