<@q5sys:matrix.org>
15:00:03
!startmeeting
<@meetbot:fedora.im>
15:00:06
Meeting started at 2026-05-21 15:00:03 UTC
<@meetbot:fedora.im>
15:00:06
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
15:00:07
!meetingname security-sig
<@meetbot:fedora.im>
15:00:09
The Meeting Name is now security-sig
<@q5sys:matrix.org>
15:00:12
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@q5sys:matrix.org>
15:00:18
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@q5sys:matrix.org>
15:00:22
!topic Open floor to discuss anything security related. (2026-05-14)
<@py0xc3:fedora.im>
15:00:29
!hi
<@zodbot:fedora.im>
15:00:31
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@thebeanogamer:fedora.im>
15:00:40
!hi
<@zodbot:fedora.im>
15:00:41
Daniel Milnes: Daniel Milnes (thebeanogamer) - he / him / his
<@q5sys:matrix.org>
15:00:43
oops wrong date...
<@q5sys:matrix.org>
15:00:45
!topic Open floor to discuss anything security related. (2026-05-21)
<@q5sys:matrix.org>
15:01:06
!topic Next Meeting (2026-05-28)
<@q5sys:matrix.org>
15:01:12
!info There are 4 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:01:14
!info There are 6 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@py0xc3:fedora.im>
15:02:20
I might have an update about fedora-downstream-hardening soon and might seek some collaboration regarding package maintaining, but that is not yet mature for a discussion here.
<@q5sys:matrix.org>
15:02:44
Keep us in the loop of there's ways we can assist
<@py0xc3:fedora.im>
15:02:53
two bugs identified, incl. one in systemd :D took some time to mitigate as it will take some time until that is fixed upstream
<@py0xc3:fedora.im>
15:04:59
anything from you Daniel Milnes
<@thebeanogamer:fedora.im>
15:05:24
Just the usual "help with the docs site please" to try and avoid the kerfuffle we had earlier in the week
<@thebeanogamer:fedora.im>
15:05:56
And a desire to buy a beer for anyone involved in kernel maintaince
<@py0xc3:fedora.im>
15:05:59
the "main page" is worth to be discussed, maybe along with re-discussing goals & targets for the SIG, but I think we might wait for a meeting with more people being here
<@py0xc3:fedora.im>
15:06:08
+1 for that
<@py0xc3:fedora.im>
15:06:44
I guess Justin will get a lot of free beer at Flock :)
<@jforbes:fedora.im>
15:06:55
Hah
<@py0xc3:fedora.im>
15:06:55
at least, I hope so ^^
<@py0xc3:fedora.im>
15:09:29
There are some reports that there are open code paths in our 204, but I guess that is already known? I didn't really follow the topic today/yesterday due to a lack of time :(
<@jforbes:fedora.im>
15:10:10
205 is building right now
<@py0xc3:fedora.im>
15:10:10
I didn't verify, but just saw the posts today: https://discussion.fedoraproject.org/t/updates-to-fix-current-security-issues-of-the-linux-kernel-dirtyfrag-fragnesia-etc-regularly-updated-topic-follow-posts/190864/24 & https://discussion.fedoraproject.org/t/updates-to-fix-current-security-issues-of-the-linux-kernel-dirtyfrag-fragnesia-etc-regularly-updated-topic-follow-posts/190864/26
<@py0xc3:fedora.im>
15:10:29
Cool, I'll update the topic then later
<@thebeanogamer:fedora.im>
15:12:04
Has anyone read into https://forge.fedoraproject.org/security/tickets/issues/7 yet?
<@q5sys:matrix.org>
15:13:34
I have not had a chance to yet
<@py0xc3:fedora.im>
15:21:51
No, but at a first skim, I am not sure if the summary of the ticket fits the blog. Also, I am wondering, if that is so serious and affecting all TPM2 (on our side?) and not just some implementations, this is not wider considered. Don't find much of this "filesystem confusion attack".
<@py0xc3:fedora.im>
15:22:28
Might be worth a skim, but actually I am reluctant to assume this is super serious. I can prepare any cryptsetup in a way that it can be broken. It would be a problem if that would be the default though
<@py0xc3:fedora.im>
15:24:05
Not the biggest fan of most tpm2 implementations anyway...
<@py0xc3:fedora.im>
15:32:19
Is anything known of the background of the many patches in 7.0.10?
<@py0xc3:fedora.im>
15:32:44
I first thought it might be a type of mass revert or so, to mitigate the impact of the current issues, but skimming rc1, this seems not the case
<@q5sys:matrix.org>
15:36:26
hey guys, I'm getting pulled into another meeting. can someone close out the meeting when you're all done.
<@py0xc3:fedora.im>
15:37:41
It's just the \!\endmeeting I think? I can do, but might need to leave myself in ~10 minutes
<@q5sys:matrix.org>
15:37:57
yup just the ! and endmeeting
<@py0xc3:fedora.im>
15:38:17
ok. I assume its not necessary to be done by the one who started (?)
<@q5sys:matrix.org>
15:41:17
nope the bot will take it from anyone.
<@py0xc3:fedora.im>
15:41:18
I think we're done anyway.
<@q5sys:matrix.org>
15:41:26
But actually since no one else is talking, I'll just end it here.
<@q5sys:matrix.org>
15:41:33
we can continue in the sec channel
<@py0xc3:fedora.im>
15:41:39
Does anyone have another point? Otherwise we can end it for today and shift everything to the channel
<@py0xc3:fedora.im>
15:41:44
Yes, true
<@py0xc3:fedora.im>
15:41:47
Shift it to channel
<@q5sys:matrix.org>
15:41:57
!endmeeting