Hi,
[ Reason ]
I would like to upload Octavia octavia_16.0.0-3+deb13u1 to
p-u to address:
https://security.openstack.org/ossa/OSSA-2026-035.html
aka:
https://bugs.debian.org/1144814
[ Impact ]
As per upstream announce:
[there is] a vulnerability in Octavia quality of service (QoS) policy
authorization. By associating another project’s QoS policy with an amphora, an
authenticated user may prevent deletion of that policy. All Octavia deployments
are affected.
[ Tests ]
The patch includes tests. I have also ran the fixes through my own CI,
so I could run functional tests.
[ Risks ]
The patch only adds a "context" object here and there, it's kind of
comprehensive.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Just a new upstream patch to fix the issue.
Please allow me to upload octavia/16.0.0-3+deb13u1 to p-u.
Cheers,
Thomas Goirand (zigo)