Bug details: ** https://bugzilla.redhat.com/show_bug.cgi?id=2243293 ** Information from BlockerBugs App:
Commented but haven't voted yet: bytehackr, pbrobinson
The votes have been last counted at 2023-10-12 18:14 UTC and the last processed comment was #comment-878435
To learn how to vote, see: https://pagure.io/fedora-qa/blocker-review A quick example: BetaBlocker +1 (where the tracker name is one of BetaBlocker/FinalBlocker/BetaFE/FinalFE/0Day/PreviousRelease and the vote is one of +1/0/-1)
BetaBlocker +1
BetaBlocker
FinalBlocker
BetaFE
FinalFE
0Day
PreviousRelease
+1
0
-1
Based on initial information here:
FinalBlocker -1
This seems to be a server-side DoS issue. Our criterion says "The release must contain no known security bugs of 'important' or higher impact according to the Red Hat severity classification scale which cannot be satisfactorily resolved by a package update (e.g. issues during installation)." The key part there is "cannot be satisfactorily resolved by a package update (e.g. issues during installation)" - I don't see how this issue meets that requirement, yet. You would not typically run an HTTP/2 server as part of installation or when running any kind of 'live' environment.
It goes against everything I know as a security professional, but I don’t think this is a release blocker. I’d be extremely surprised if someone is running an internet-facing web server from a live USB. That being said, I would support an FE for this.
Don't see why this can't be addressed with a post release update.
For the general services having it available as a zero day IMO is fine but Workstation uses httpd as part of gnome-user-share so that would be running on a live image so I believe having that explicit update (RHBZ 2243247) as a blocker would be useful.
So I would do FinalBlocker (httpd) +1 and -1 for all of the fixes overall.
Turns out httpd isn't affected. (Although it's still not super clear exactly what else is).
AGREED RejectedFinalBlocker
The following votes have been closed:
Metadata Update from @blockerbot: - Issue status updated to: Closed (was: Open)
Release F39 is no longer tracked by BlockerBugs, closing this ticket.
Log in to comment on this ticket.