https://bugs.debian.org/1024932 ceph-base: ceph to root privilege escalation via ceph-crash.service CVE-2022-3650

2022-11-30 Thread Thomas Goirand
Hi, The patch is kind of trivial Python stuff backporting work. Can someone take care of it in Buster? I'm currently building the Bullseye backport of the fix... Cheers, Thomas Goirand (zigo)

Re: Updating OpenStack compute (aka src:nova) in Buster

2022-09-14 Thread Thomas Goirand
On 9/14/22 13:37, Emilio Pozuelo Monfort wrote: Hi Thomas, On 11/09/2022 12:50, Thomas Goirand wrote: Hi, In the OpenStack team git, there are updates for nova 2:18.1.0-6+deb10u1 (CVE-2019-14433/ OSSA-2019-003). Can someone pick it up and upload it to Buster? It was never accepted in Buster

Updating OpenStack compute (aka src:nova) in Buster

2022-09-11 Thread Thomas Goirand
pting / rejecting uploads for LTS? Cheers, Thomas Goirand (zigo)

Re: EOL candidates for security-support-ended.deb10 (OpenStack support)

2022-08-08 Thread Thomas Goirand
need to test regressions. As pochu mentioned, we normally support packages in LTS unless there's a solid reason /not/ to, and reading this conversation we appear to be in capacity of supporting OpenStack Rocky packages in buster LTS. Great, I'll make the announcement then! :) Cheers, Thomas Goirand (zigo)

Re: EOL candidates for security-support-ended.deb10

2022-08-06 Thread Thomas Goirand
. Also in the past, I had help from upstream (in Nova) for some nasty fixes hard to backport. I do expect help again. If we take this decision, I'd like to announce it on the openstack-discuss list, so let's make it clear what route we're taking. Thomas Goirand (zigo)

Re: EOL candidates for security-support-ended.deb10

2022-08-03 Thread Thomas Goirand
penStack project, 11 years ago. So, are we going to continue support OpenStack Rocky in Buster LTS? Please let me know. I hope that helps, Cheers, Thomas Goirand (zigo)

Re: Update of OpenVSwitch in Stretch

2021-02-19 Thread Thomas Goirand
ahead and upload. I could test it, though that would mean a full OpenStack deployment, and that's really a lot of work, especially in Stretch where I don't have all the tooling. Thanks for the work, Cheers, Thomas Goirand (zigo)

Re: Update of OpenVSwitch in Stretch

2021-02-15 Thread Thomas Goirand
ixes bugs in the stable branches without adding features, and a few times, after I encounter bugs (OVS crash in my case, for the 2.10.0 currently in Buster), upgrading to the tip of the stable branch fixed my cluster. That's why the last CVE fix I uploaded are just an upgrade to the latest point release from upstream. Cheers, Thomas Goirand (zigo)

Update of OpenVSwitch in Stretch

2021-02-15 Thread Thomas Goirand
retch doesn't have any upstream support. Your thoughts? Can anyone from the team do it? Cheers, Thomas Goirand (zigo)

Re: Taking care of Keystone in Stretch and Jessie

2020-05-15 Thread Thomas Goirand
On 5/15/20 3:12 PM, Sylvain Beucler wrote: > Hi Thomas, > > On 14/05/2020 19:08, Thomas Goirand wrote: >> I released an update of Keystone for a quite serious problem related to >> ec2 credentials where a user can become admin. I was able to fix the >> last 4 releases o

Taking care of Keystone in Stretch and Jessie

2020-05-14 Thread Thomas Goirand
isn't even affected, I don't know. Is anyone interested to do the work? If so, best would be to look at the 4 patches I added to the security release of Keystone in Buster. Cheers, Thomas Goirand (zigo)

Availability of SACKS fix for Linux 4.9.x in Jessie

2019-06-25 Thread Thomas Goirand
Hi Ben and everyone else, Is $subject plan, and what's the ETA? Thanks in advance for your reply, Cheers, Thomas Goirand (zigo)

Re: Jessie update of miniupnpd?

2019-06-07 Thread Thomas Goirand
On 5/29/19 3:04 PM, Thomas Goirand wrote: > I'm not familiar with the workflow either, and it's a single line patch, > so I guess it's best to just leave this work to the LTS team. > > Cheers, > > Thomas Goirand (zigo) Hi, The team probably wants to als

Re: Jessie update of miniupnpd?

2019-05-29 Thread Thomas Goirand
y-tracker/raw/master/data/dla-needed.txt > > Hi LTS team, > > I'm not familiar with the workflow, nor do I have much spare time > these days. So I'm afraid I can't help at least for this update. You > may ask zigo for his opinions. > > Thanks, > Yangfl I'm not familiar with the workflow either, and it's a single line patch, so I guess it's best to just leave this work to the LTS team. Cheers, Thomas Goirand (zigo)

Re: Security update in Jessie for intel-microcode and linux?

2019-05-15 Thread Thomas Goirand
On 5/15/19 2:51 PM, Ben Hutchings wrote: > On Wed, 2019-05-15 at 13:59 +0200, Thomas Goirand wrote: >> Hi, >> >> Probably Ben will reply to this one... >> >> Is it planned to upgrade intel-microcode and the kernel in Jessie, >> regarding CVE-2018-12126 CVE-2

Security update in Jessie for intel-microcode and linux?

2019-05-15 Thread Thomas Goirand
Hi, Probably Ben will reply to this one... Is it planned to upgrade intel-microcode and the kernel in Jessie, regarding CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2019-11091? Cheers, Thomas Goirand (zigo)

Re: linux backport in jessie LTS

2018-04-23 Thread Thomas Goirand
4.9 backport to the > regular jessie and jessie-security suites? Are there users currently > running jessie with Linux 4.9 and expecting to continue doing so > through the LTS period? By all means, YES ! Cheers, Thomas Goirand (zigo)

Re: Wheezy update of miniupnpc?

2017-05-27 Thread Thomas Goirand
ion of the package, including all security fixes. However, upstream is very cooperative, and he may accept to write patches for Wheezy if asked. He's Cc-ed to this mail. Cheers, Thomas Goirand (zigo)

Re: Wheezy update of rabbitmq-server?

2017-01-04 Thread Thomas Goirand
Hi, I don't think any of the maintainers of RabbitMQ cares about Wheezy anymore, so it'd be very nice if someone from the LTS team was taking care of it. Cheers, Thomas Goirand (zigo) On 12/30/2016 11:16 PM, Ola Lundqvist wrote: > Hi > > I forgot to mention that I do not h

Re: Wheezy update of extplorer?

2016-07-21 Thread Thomas Goirand
is mail doesn't match the content. What package are we talking about here? Cheers, Thomas Goirand (zigo)

Re: Unsupported packages for Wheezy LTS

2015-11-04 Thread Thomas Goirand
rted upstream und very unlikely >>>> to be used since OpenStack is evolving so fast. You should discuss >>>> that with Thomas Goirand. >>> >>> Thomas, what's your stance on this? > > While Thomas did not reply directly, I discussed with him on

Re: Interest in ia32-libs for squeeze-lts

2014-07-11 Thread Thomas Goirand
On 07/11/2014 02:55 PM, Thijs Kinkhorst wrote: > All, > > I was wondering if there's interest for the ia32-libs package to be > maintained in squeeze-lts. > > The ia32-libs package contains 32 bit versions of various libraries which > can be installed on amd64, so you can run 32 bit applications