The CVE is now officially disputed : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29072 And Kagan Capar is getting is ass laugh at by CERT own researchers : https://twitter.com/wdormann/status/1516217431437500419 IMO, it look like there is nothing to fix there