Note that someone created various CVEs for #elfutils based on (fixed and closed) bug reports without following our SECURITY policy: https://sourceware.org/cgit/elfutils/tree/SECURITY
These are NOT security issues according to our policy.
We request that people who report suspected security vulnerabilities report them through the contacts in our SECURITY policy and not through non-affiliated CNAs.
Creating random CVEs without coordinating with the upstream project and designated CNA just causes lots of make work.