Wednesday, 2024-03-13

mgariepyanyone knows if there are patches to mitigate these for neutron ? https://mail.openvswitch.org/pipermail/ovs-discuss/2024-March/052994.html13:18
fungimgariepy: you mean without upgrading ovn?13:44
mgariepyhmm yeah by right upgrading ovn would also fix it.13:45
mgariepybut i was wondering if neutron would need to change some acl also.13:45
funginot sure, might be worth asking folks in #openstack-neutron about. the openstack vmt doesn't officially track vulnerabilities in dependencies, and recommend consumers rely on curated distributions to provide them since their package maintainers handle the backporting of security fixes to contemporary releases of those dependencies13:47
mgariepyfair enough13:51
mgariepythanks13:51
fungilooking closer at the ovn advisory, they already provide backports to 5 different versions, so it's probably pretty well covered and i would expect patching or minimally upgrading should be safe13:52
mgariepyyeah distro will probably publish updates soon-ish :D13:53
fungisince it's not a python-based dependency, i'm not even sure whether neutron is overly reliant on specific ovn versions anyway13:54
fungii expect it's just whatever version is provided on the distros we test upstream13:54
mgariepyi guess some feature needs some version of ovn pretty much like nova and libvirt does13:55
fungiright, but basically as long as whatever we're testing with also gets security patches, we'll be testing against the patched versions13:56
fungieven for stable branches13:56
mgariepyyep14:08
*** blarnath is now known as d34dh0r5314:51
opendevreviewMerged openstack/security-doc master: Add OSSN-0093  https://review.opendev.org/c/openstack/security-doc/+/91202816:35

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!