Tuesday, 2026-07-28

opendevreviewSofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes  https://review.opendev.org/c/openstack/security-doc/+/99886100:15
fungihttps://heyitsas.im/posts/ovswrap might be interesting to folks here13:54
fungi(CVE-2026-64531 is a local privilege escalation via a bug in open vswitch)13:56
gouthamrhttps://bugs.launchpad.net/ossa/+bug/2158733 is now public14:07
gouthamrhttps://bugs.launchpad.net/ossa/+bug/2158771 is now public14:07
* gouthamr is still waking up, these bugs are14:08
gouthamr:14:08
gouthamrhttps://bugs.launchpad.net/swift/+bug/215877114:08
gouthamrhttps://bugs.launchpad.net/swift/+bug/2158733 14:08
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99895914:29
gouthamrcschwede: fungi ^ this could use your review14:43
fungilooking now, thanks!14:48
fungigouthamr: looking at the version strings, is 2.38.0 (already tagged for hibiscus) also affected?14:52
fungiit was tagged on 2026-07-09 so i'm guessing not14:53
fungii'm still double-checking all the urls14:53
fungithe preview build and urls all lgtm though14:57
gouthamrah, I may have missed that - looking14:57
fungier, i mean guessing it's not safe (i.e. is affected)15:00
fungiso probably want to do that as a quick revision, could be a follow-up change if you want to just hand-edit it into the announcements, your call15:01
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99895915:06
fungiapproved, thanks!!!15:07
gouthamrthanks for flagging it fungi!15:09
cschwedefungi++15:10
fungiglad i remembered to check15:10
* gouthamr preps emails15:10
fungiwe're getting to that point in the cycle where some projects are tagging hibiscus versions already if they're not cycle-with-rc release model15:11
gouthamryes, i should keep that in mind15:12
fungi(we don't count milestone/prerelease/candidate versions as "affected" but in this case it's a potential "final" release)15:12
gouthamroh15:13
gouthamryou're making a distinction about the release model15:14
fungiyes15:14
fungiit comes up when we have vulnerabilities affecting clients/libraries that release ahead of the coordinated release day too15:14
gouthamr++ yeah certainly15:15
fungihistorically it was a rare occurrence, but we now live in interesting times15:16
gouthamrindeed15:24
opendevreviewMerged openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99895915:25
fungipromote completed, should publish with the 15:30 utc afs vos release15:27
gouthamr\o/15:27
gouthamri sent emails15:28
fungiboth look good, accepted through openstack-announce moderation now15:29
gouthamrty fungi, will inform MITRE and do erratas when they respond with a CVE15:29
gouthamrspeaking of, we never got an assignment for OSSA-2026-007 15:30
fungihttps://security.openstack.org/#openstack-security-advisories-ossa is has 030 and 031 now15:30
gouthamriirc, i filed that one multiple times, assuming there was something wrong 15:30
* gouthamr will find and file his request again with the new form :|15:31

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!