https://bugs.openldap.org/show_bug.cgi?id=9202
--- Comment #9 from Quanah Gibson-Mount quanah@openldap.org --- (In reply to Michael Ströder from comment #8)
Please add the CVE-Id to CHANGES so downstream packagers take note of it.
That's currently not a tracked item in the format of the CHANGES file.
I have been thinking of adding a customized field to bugzilla to track CVEs (we did that at a prior job I worked at).
We may want to consider a format change for RE25 to allow for CVEs in the CHANGES file as well.