No, we don't, because then we'd have to more widely disclose the issue. Needs to be handled under extreme secrecy and embargoed disclosure while we design a mitigation...


On Fri, Feb 18, 2022 at 9:11 AM Nick Hilliard <> wrote:
Warren Kumari wrote on 18/02/2022 15:02:
> This was the same person who alerted me to the also *shocking* discovery
> that longest-match wins, and so just twiddling local-pref doesn't save you.

Ye gods, do we have a CVE number for this?

Perhaps they really do strive for incomprehensibility in their specs.
After all, when the liturgy was in Latin, the laity knew their place.
-- Michael Padlipsky