Comment 14 for bug 1902917

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Anti-spoofing bypass using Open vSwitch

Summer: I was hoping to first see some core reviews on the proposed backports before assuming it's going to be fixed there, and as confirmation that we know for sure the extent of the problem prior to the current state of the master branch. The backport targeting stable/victoria looks like it may also fail the neutron-grenade-dvr-multinode upgrade job, it was rechecked a few minutes ago to hopefully rule that out.

Once there's at least one +2 on some of the backports I'll be more confident in drafting an accurate impact description with which to request a CVE assignment. Since this is already public, we're not under any tight embargo timeline with it, and probably not much point in having a CVE to track it until we have a fix we know we can recommend. That said, if you want to act as a CNA and issue a placeholder CVE now, just make sure to let us know the number and I'll refrain from requesting one from MITRE later.