Since joining the Common Vulnerabilities and Exposures (CVE) Program in 2002, Red Hat has been committed to excellence, growth and innovation in product security. Today, we’re pleased to announce that Red Hat is now a CVE Numbering Authority of Last Resort (CNA-LR), a prestigious recognition of our leadership, expertise and continued commitment to industry advancement. This achievement is a testament to Red Hat’s dedication and a significant success for the entire open source software (OSS) community of which we are proud to be a part.
Red Hat’s role as a CNA remains, with the company being responsible for assigning CVE identifiers to vulnerabilities that affect open source software, particularly those that impact Red Hat’s products and associated upstream projects. Since 2022, Red Hat has served as a Root organization in the CVE Program, onboarding and mentoring open source software projects to succeed within the Program. Check out the blog, “Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization” for more details. CNA-LR extends this role further, enabling Red Hat to assign CVE IDs and to publish corresponding CVE records within Red Hat Root’s scope for vulnerabilities NOT covered by another CNA.
For example, if the Red Hat Root determines that a CNA within its hierarchy has refused to assign a CVE for any reason, Red Hat, as a CNA-LR, may assign a CVE for that reported vulnerability at the conclusion of the dispute process. You can find all information in the Red Hat CNA-LR Operational Guide.
For over two decades, Red Hat has actively contributed to the goals and initiatives of the CVE Program. Gaining a CNA-LR designation signifies our unwavering dedication and the trust and recognition we have earned within the program. This milestone reflects our relentless pursuit of excellence, strong collaborations and impactful contributions to industry standards and best practices. Additionally, it reinforces the collective strength of the OSS community, whose collaboration and support have been integral to our success.
What this means for you
Achieving CNA-LR status in the CVE Program provides us with new opportunities to help shape the future of our vulnerability ecosystem. With this elevation, we gain access to:
- Greater influence: A stronger voice for the open source software community in the CVE Program
- Stronger collaboration: Enhancing our work with more open source software maintainers and the broader community
- Continued innovation: A platform to drive cutting-edge advancements and thought leadership
A heartfelt thank you
This achievement would not have been possible without the unwavering dedication of our team, the support of our open source community, and the trust of the CVE Program. We extend our deepest gratitude to everyone who has contributed to our journey and helped us reach this significant milestone. We want to thank our open source software community group, whose ongoing support has played a vital role in this success.
What’s next
As we step into this new chapter, we remain committed to driving progress, fostering innovation, and upholding the highest standards of excellence. Our elevation to CNA-LR is an achievement and a stepping stone toward even more outstanding contributions to the industry and open source software community.
Stay tuned for more updates as we continue our journey of leadership and excellence. Thank you for being part of Red Hat’s success story!
저자 소개
Pete Allor is the Director for Red Hat Product Security covering the full Red Hat portfolio. He is active in various industry security forums for incident response reporting and secure development, such as NIST and CISA industry calls for input as well as FIRST (first.org), CVE and ISO / ITU / OASIS standards on security.
He is a former Board of Directors Member of FIRST, the Information Technology ISAC and a member of the Executive Board for the IT Sector Coordinating Council. Allor previously worked for Internet Security Systems, IBM and Honeywell. He is a retired US Army Officer.
Yogesh Mittal is a Product Security Manager at Red Hat, primarily focusing on vulnerability management and incident response. He participates in various industry working groups focused on improving vulnerability coordination and disclosure processes.
채널별 검색
오토메이션
기술, 팀, 인프라를 위한 IT 자동화 최신 동향
인공지능
고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트
오픈 하이브리드 클라우드
하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요
보안
환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보
엣지 컴퓨팅
엣지에서의 운영을 단순화하는 플랫폼 업데이트
인프라
세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보
애플리케이션
복잡한 애플리케이션에 대한 솔루션 더 보기
오리지널 쇼
엔터프라이즈 기술 분야의 제작자와 리더가 전하는 흥미로운 스토리