Thursday, 2026-05-28

sean-k-mooneyso this is a thing https://www.redhat.com/en/about/press-releases/project-lightwell-secure-open-source https://www.ibm.com/products/lightwell13:13
sean-k-mooneyits a redhat ibm version of i guess https://www.anthropic.com/glasswing13:13
sean-k-mooneyno real ideay of what that actully means in practice but this was apprently jsut anouchned13:14
sean-k-mooney... i hate when compaiens do joint anouchment that pingpong you from a to b back to a differnt part of a13:16
sean-k-mooneyhttps://www.redhat.com/en/lightwell13:16
sean-k-mooneyreadinbg between the line this is perhaps more focused on teh "how do you deleiver the security fix in the old enterpise version" more then just how do you fix it13:21
sean-k-mooneyso not actully sure how much of this would be applicabel upstream13:21
sean-k-mooney"Red Hat scans, backports, tests, signs, and delivers patched artifacts at the customer's pinned version. Patches are contributed upstream simultaneously." that imples that there would be an upstream compoent but woudl not be entrilly correct chronologiclaly as it shoudl eb fixed upstream first with teh cusotemr delviery soon there after13:23
sean-k-mooneybut then again those sits are defeinly more marketing and custoemr focus then engeinering focused13:24
fungiyeah, hard to read between the lines of marketing and hype in those press releases13:33
JayFI basically just assume it's all hype. If it's something of value I'll hear about it in a better way than their own press releases.14:20
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2150089 is now public15:06
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2149789 is now public15:06
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2148477 is now public15:06
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2148398 is now public15:06
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2150379 is now public15:06
gouthamrthese are related to:15:06
gouthamrhttps://bugs.launchpad.net/keystone/+bug/2149775 which has been publicly addressed a while ago15:06
gouthamrgtema: thanks for the fixes.. will upload the ossa now, would appreciate a review 15:41
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-016 (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394)  https://review.opendev.org/c/openstack/ossa/+/99052415:41
gtemaok, doing it now15:41
gouthamri will have to renumber.. 015 hasn't merged yet15:43
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-015 (multiple CVEs)  https://review.opendev.org/c/openstack/ossa/+/99052615:43
* gouthamr fixed the long title, will seek advice from vmt vets if that's okay15:44
fungilooking!15:45
gouthamrthank you fungi 15:45
fungii like the title, good work15:45
fungithe impact description is unavoidably lengthy15:45
fungibut well-written and comprehensive without including unnecessary detail15:47
fungiaffected versions list looks correct, double-checked the releases site15:48
fungigouthamr: oh, i was reviewing 990524 which you abandoned. can i assume 990526 is identical aside from the ossa number?15:51
fungii assume you accidentally blew away the change-id in the commit message which caused it to be a new change instead of just a revision to that one15:52
gouthamryes, rookie mistake ten years in15:52
funginah, happens to me too15:52
gouthamrfungi: do you prefer i restore the CVE numbers onto the title?15:53
fungino it's fine15:53
gouthamrthank you :) 15:53
fungii'll double-check the preview render as soon as zuul reports15:54
gouthamr++15:54
gouthamrgtema: thank you for your hard work on this! 15:54
gtemasure15:55
fungialso is 990398 ready to review once the ossa number gets incremented?15:55
gouthamryes, i'm editing it now.. will push it back up15:55
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-016 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99039816:01
opendevreviewMerged openstack/ossa master: Add OSSA-2026-015 (multiple CVEs)  https://review.opendev.org/c/openstack/ossa/+/99052616:16
* gouthamr writes email16:19
fungigouthamr: 990398 has yesterday's date, if you bump that to current i'll reapprove16:20
gouthamryes16:20
fungiand yeah, OSSA-2026-015 is live on the security site now as of a few seconds ago16:20
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-016 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99039816:21
fungithanks!16:21
fungithat's now on the way in too16:21
gouthamrthank you fungi!16:22
fungino, thank you! (and everyone else involved)16:22
fungii did the easy part16:22
opendevreviewMerged openstack/ossa master: Add OSSA-2026-016 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99039816:28
fungigouthamr: OSSA-2026-016 is live too as of the past ~10 minutes16:39
gouthamrty, email incoming :) 16:44
* gouthamr informed MITRE about CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394.. will post on the bugs too16:44
zigogouthamr: Are versions of neutron before Epoxy not affected by OSSA-2026-016 ? Or should I also do the backports ?16:46
gouthamrzigo: yes, the bug was introduced in 2025.116:47
zigoOk, thanks.16:47
fungiconfirmed, i checked that in the bug when reviewing the advisory16:47
fungii suppose it's possible the bug got backported to an earlier stable branch like happened with ossa-2026-014 but i found no evidence that was the case (it came in with feature work so shouldn't have been backport-eligible regardless)16:48
gouthamrhttps://bugs.launchpad.net/ossn/+bug/2150121 is now public18:16

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!