15:00:46 #startmeeting security 15:00:56 Meeting started Thu Mar 14 15:00:46 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:58 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:01:01 The meeting name has been set to 'security' 15:01:17 * gagehugo dislikes DST 15:01:22 ping fungi gagehugo lhinds nickthetait browne redrobot 15:01:35 #link https://etherpad.openstack.org/p/security-agenda agenda 15:01:37 o/ 15:01:49 aloha 15:02:17 * fungi is also in tc office hour and trying to nail down ci job failures due to yesterday's default node change 15:02:36 yeah I'm dual meetings right now :) 15:03:26 So there's a new CVE for one of the bugs listed last week 15:03:31 #link https://bugs.launchpad.net/neutron/+bug/1818385 15:03:33 Launchpad bug 1818385 in neutron "It's possible to add a security group rule for VRRP with a dport (CVE-2019-9735)" [Critical,In progress] - Assigned to Brian Haley (brian-haley) 15:04:09 In a work meeting, so only partially o/ 15:04:25 #link https://nvd.nist.gov/vuln/detail/CVE-2019-9735 15:05:04 There was also another public security bug reported regarding caching 15:05:08 #link https://bugs.launchpad.net/oslo.cache/+bug/1819957 15:05:10 Launchpad bug 1819957 in oslo.cache "Caching with stale data when a server disconnects due to network partition and reconnects" [High,New] - Assigned to Morgan Fainberg (mdrnstm) 15:07:23 Also does anyone know if they will make it to the PTG? I'd like to get a somewhat official estimate so I can book a space for us 15:09:43 well I will be there 15:10:11 \o/ 15:12:35 #link https://etherpad.openstack.org/p/DEN-securitysig-topics 15:12:57 If you are planning to attend and/or have a topic you want to discuss, feel free to put it down there ^ 15:14:14 Did anyone have anything they wanted to talk about this week? 15:16:00 on 1818385 i think we're still waiting on the stable/pike fix to merge before issuing an advisory, but i haven't had time to look at it again this morning 15:16:42 there's also public bug 1813007 which is quite possibly needing an advisory but would be useful if someone could help nudge the diagnosis along 15:16:44 bug 1813007 in neutron "Unable to install new flows on compute nodes when having broken security group rules" [Critical,In progress] https://launchpad.net/bugs/1813007 - Assigned to IWAMOTO Toshihiro (iwamoto) 15:26:16 fungi ack 15:28:15 Luzi redrobot fungi if you know of any topics for the PTG please feel free to add it to the etherpad, I will get a room booked for us for probably a day 15:28:36 otherwise, everyone have a good rest of the week & weekend! 15:28:44 * gagehugo has another meeting :( 15:28:49 thanks for coming everyone! 15:28:51 thanks! 15:28:51 #endmeeting