On 7/26/26 20:07, Marc-André Lureau wrote:
...>> Unfortunately this (additional) fix does not mention the
previous fix, so there's some confusion about which commit
actually fixed this issue. It looks like the first fix was
incomplete and this additional fix were needed.
That's correct, we reused the same CVE
Daniel P. Berrangé said on the issue:
We didn't release master yet. As long as we also didn't release any
stable branches that claimed to fix it, we could re-use it IMHO.
Heh. This is exactly what actually happened - there were
2 stable releases on Jun-25 (v10.0.11 and v11.0.2) which
contained the first half. Now there are 2 more stable
releases from Jul-24 which contains the second half.
Unfortunately I haven't noticed this duplicated CVE#,
or else I'd add a note to the second half in the stable
pick-ups.
I know you don't like me rushing things to the stable
series, and this is an example why this might be bad.
Fortunately this is not a regression, at least. And
usually security fixes come in faster anyway. Ohwell..
I'm sorry to disappoint you further.
Anyway, thank you for the clarification - everything's
clear now, the confusion is no-more.
Thank you!
/mjt