| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes https://review.opendev.org/c/openstack/security-doc/+/998861 | 00:15 |
|---|---|---|
| fungi | https://heyitsas.im/posts/ovswrap might be interesting to folks here | 13:54 |
| fungi | (CVE-2026-64531 is a local privilege escalation via a bug in open vswitch) | 13:56 |
| gouthamr | https://bugs.launchpad.net/ossa/+bug/2158733 is now public | 14:07 |
| gouthamr | https://bugs.launchpad.net/ossa/+bug/2158771 is now public | 14:07 |
| * gouthamr is still waking up, these bugs are | 14:08 | |
| gouthamr | : | 14:08 |
| gouthamr | https://bugs.launchpad.net/swift/+bug/2158771 | 14:08 |
| gouthamr | https://bugs.launchpad.net/swift/+bug/2158733 | 14:08 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998959 | 14:29 |
| gouthamr | cschwede: fungi ^ this could use your review | 14:43 |
| fungi | looking now, thanks! | 14:48 |
| fungi | gouthamr: looking at the version strings, is 2.38.0 (already tagged for hibiscus) also affected? | 14:52 |
| fungi | it was tagged on 2026-07-09 so i'm guessing not | 14:53 |
| fungi | i'm still double-checking all the urls | 14:53 |
| fungi | the preview build and urls all lgtm though | 14:57 |
| gouthamr | ah, I may have missed that - looking | 14:57 |
| fungi | er, i mean guessing it's not safe (i.e. is affected) | 15:00 |
| fungi | so probably want to do that as a quick revision, could be a follow-up change if you want to just hand-edit it into the announcements, your call | 15:01 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998959 | 15:06 |
| fungi | approved, thanks!!! | 15:07 |
| gouthamr | thanks for flagging it fungi! | 15:09 |
| cschwede | fungi++ | 15:10 |
| fungi | glad i remembered to check | 15:10 |
| * gouthamr preps emails | 15:10 | |
| fungi | we're getting to that point in the cycle where some projects are tagging hibiscus versions already if they're not cycle-with-rc release model | 15:11 |
| gouthamr | yes, i should keep that in mind | 15:12 |
| fungi | (we don't count milestone/prerelease/candidate versions as "affected" but in this case it's a potential "final" release) | 15:12 |
| gouthamr | oh | 15:13 |
| gouthamr | you're making a distinction about the release model | 15:14 |
| fungi | yes | 15:14 |
| fungi | it comes up when we have vulnerabilities affecting clients/libraries that release ahead of the coordinated release day too | 15:14 |
| gouthamr | ++ yeah certainly | 15:15 |
| fungi | historically it was a rare occurrence, but we now live in interesting times | 15:16 |
| gouthamr | indeed | 15:24 |
| opendevreview | Merged openstack/ossa master: Add OSSA-2026-030 and OSSA-2026-031 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998959 | 15:25 |
| fungi | promote completed, should publish with the 15:30 utc afs vos release | 15:27 |
| gouthamr | \o/ | 15:27 |
| gouthamr | i sent emails | 15:28 |
| fungi | both look good, accepted through openstack-announce moderation now | 15:29 |
| gouthamr | ty fungi, will inform MITRE and do erratas when they respond with a CVE | 15:29 |
| gouthamr | speaking of, we never got an assignment for OSSA-2026-007 | 15:30 |
| fungi | https://security.openstack.org/#openstack-security-advisories-ossa is has 030 and 031 now | 15:30 |
| gouthamr | iirc, i filed that one multiple times, assuming there was something wrong | 15:30 |
| * gouthamr will find and file his request again with the new form :| | 15:31 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!