google / google/osv.dev

Discrepancies found with Debian CVE(s)

Open
#4,161 2 comments 0 reactions 1 assignee Claimed by @jess-lowe View on GitHub
Dominant language
Go
Stars
2.9k
Forks
369
Avg merge
1d 17h
Merged PRs (30d)
149

Description

Data Used from: https://osv-vulnerabilities.storage.googleapis.com/Debian/all.zip
Source used to compare against: https://security-tracker.debian.org/tracker

Case 1
---
CVE Entries marked as "NOT-FOR-US" included in the ZIP.

Example: DEBIAN-CVE-2025-0649
https://security-tracker.debian.org/tracker/CVE-2025-0649
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-0649.json

Case 2
---
CVE Entries marked as Rejected by both Debian and NVD included in the ZIP.

Example: DEBIAN-CVE-2023-52979
- Sources
- https://security-tracker.debian.org/tracker/CVE-2023-52979 (Empty Page)
- https://salsa.debian.org/security-tracker-team/security-tracker/-/raw/master/data/CVE/list (Specifically marked as Rejected)
- OSV
- https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52979.json (No Indicating values to show Rejected status)

Case 3
---
Few CVE entries have wrong Debian versions marked as affected in the ZIP.

Example: DEBIAN-CVE-2025-52566
We can see that only the unstable release is mentioned at the source (Debian Security Tracker).
https://security-tracker.debian.org/tracker/CVE-2025-52566
But Debian:14 is mentioned here,
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-52566.json

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.