Skip to content
Discussion options

You must be logged in to vote

Hi,

Unfortunately, most CVE records only list the release version an issue was fixed, and not the actual commit it was fixed in.

We do have some CVE records that have versions sourced from git commits. From what I can remember, Linux Kernel vulnerabilities usually include exact commits for patches.

Otherwise, I'm not sure if OSV has a way to tell whether a commit points to an actual patch or a release version. @jess-lowe would know more, but may not be able to get back to you this week.

Our CVE data is mostly converted from the cvelistV5 repo - you may have some luck trying to search commit hashes directly in there, but that might also require some manual verification.

Besides our convert…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@NikolausReichsoellner
Comment options

Answer selected by NikolausReichsoellner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants