google / oss-fuzz-vulns

OSS-Fuzz vulnerabilities for OSV.

Home Page:

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[matio] How to fix/remove 2021-440?

tbeu opened this issue · comments


CVE-2020-36428 = OSV-2021-440 = is considered invalid. How can both CVE and OSV be marked as fixed?

@fyi @inferno-chromium

It's not fixed according to the OSV. has an "introduced" event only, and no "fixed" event.

We also don't generate the CVE -- someone else is taking our entries and generating them.


Yes, I know, it is not marked as fixed in the yaml file. But I thought it is considered a false-positive issue and wondered how to deal with it.

Ah, I misunderstood your question. After your PR, is marked as fixed, thanks!