Summary
OpenAI reports that Codex Security independently recognized vulnerable patterns matching four of the six CVEs fixed in dnsmasq 2.92rel2. The dnsmasq maintainer publishes per-CVE credit and patch files for the release.
The entry counts only the four identifiers OpenAI names. It does not absorb the other two release CVEs or OpenAI’s broader private campaign totals.
Attribution
OpenAI’s primary disclosure establishes the AI-system role, while dnsmasq’s maintainer archive independently establishes the accepted patches and release.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.