As the person who wrote the fix for this issue (and not the original code), I will just mention that I find this paragraph makes the author sound incredibly entitled:
Shamefully, the inetutils project hasn’t actually released a fixed version of their software (at least at the time of publishing).
The bug was reported on a public mailing list, which is sadly common nowadays [1]. After my workday, during which I was not able to review the report, I wrote a script to confirm the bug was real, since I was seeing way too many slop reports at the time. Then I sent a patch before going to bed [2]. A third party then graciously shared the patch on oss-security [3], which all distributions follow. There is no need to make a new release, which is harder for the distributions than simply applying a small patch.
Perhaps I am just unlucky in my interactions, but I feel like this entitlement is too common among software security people. Note that I see zero return in spending time working on Inetutils, and I find other projects I work on more interesting.
The bug was reported on a public mailing list, which is sadly common nowadays
In defence of the reporter, your Readme only says "Send bug reports to bug-inetutils@gnu.org.", there is no distinction for vulnerabilities. [1]
There is a 3 months old pull request to advertise a private reporting email address but it's unmerged, maybe you could use this renewed interest as a nudge to set it up and merge: <a href="https://codeberg.org/inetutils/inetutils/pulls/26" rel="nofollow">https://codeberg.org/inetutils/inetutils/pulls/26
One other thing the reporter could have done to make your life easier is to write a repro script rather than just explain the steps in prose.
collinfunk · · focus · HN ↗
Perhaps I am just unlucky in my interactions, but I feel like this entitlement is too common among software security people. Note that I see zero return in spending time working on Inetutils, and I find other projects I work on more interesting.
[1] <a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html" rel="nofollow">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [2] <a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00032.html" rel="nofollow">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg... [3] <a href="https://www.openwall.com/lists/oss-security/2026/03/12/4" rel="nofollow">https://www.openwall.com/lists/oss-security/2026/03/12/4
croemer · · focus · HN ↗
There is a 3 months old pull request to advertise a private reporting email address but it's unmerged, maybe you could use this renewed interest as a nudge to set it up and merge: <a href="https://codeberg.org/inetutils/inetutils/pulls/26" rel="nofollow">https://codeberg.org/inetutils/inetutils/pulls/26
One other thing the reporter could have done to make your life easier is to write a repro script rather than just explain the steps in prose.
[1]: <a href="https://codeberg.org/inetutils/inetutils/src/commit/40f19d84c3dead93e6fef7fc1150fde5210ebdab/README.md?display=source#L8" rel="nofollow">https://codeberg.org/inetutils/inetutils/src/commit/40f19d84...