I'll put something into Bugzilla once they agree with my patch and commit it.
Filing it in Buzilla with severity "security" means that the RH security folks get involved and put more pressure on the upstream. They can also get the word out to other distros' security groups.