Skip to content

OBSDOCS-3619: Add Logging 6.2.12 z-stream release notes#115879

Open
johnwilkins wants to merge 3 commits into
openshift:standalone-logging-docs-6.2from
johnwilkins:OBSDOCS-3619
Open

OBSDOCS-3619: Add Logging 6.2.12 z-stream release notes#115879
johnwilkins wants to merge 3 commits into
openshift:standalone-logging-docs-6.2from
johnwilkins:OBSDOCS-3619

Conversation

@johnwilkins

@johnwilkins johnwilkins commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

Changes

  • Created modules/logging-release-notes-6-2-12.adoc with bug fix and CVE sections
  • Updated release_notes/logging-release-notes-6.2.adoc to include new module

Fixed Issues

  • LOG-9636: Vector terminationGracePeriodSeconds hardcoded to 10s causes SIGKILL and disk buffer corruption

CVEs Included

  • CVE-2026-25681: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
  • CVE-2026-32281: Go crypto/x509: Denial of Service via inefficient certificate chain validation
  • CVE-2026-32282: Root.Chmod can follow symlinks out of the root
  • CVE-2026-34986: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
  • CVE-2026-39821: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing

Follow-up

Errata number placeholder (RHSA-YYYY:NNNNN) will need to be updated once the actual errata is available.

JIRA: https://redhat.atlassian.net/browse/OBSDOCS-3619

Signed-off-by: John Wilkins jowilkin@redhat.com

🤖 Generated with Claude Code

This release contains 1 bug fix and 5 CVEs. Errata number placeholder
will be updated once the actual errata number is provided.

Bug fixes:
- LOG-9636: terminationGracePeriodSeconds hardcoded to 10s causes disk buffer corruption

CVEs:
- CVE-2026-25681
- CVE-2026-32281
- CVE-2026-32282
- CVE-2026-34986
- CVE-2026-39821

Signed-off-by: John Wilkins <jowilkin@redhat.com>

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@openshift-ci-robot

openshift-ci-robot commented Jul 20, 2026

Copy link
Copy Markdown

@johnwilkins: This pull request references OBSDOCS-3619 which is a valid jira issue.

Details

In response to this:

Summary

  • Adds release notes for OpenShift Logging 6.2.12 z-stream release
  • Includes 1 bug fix and 5 CVEs
  • Uses errata placeholder pending actual errata number

Changes

  • Created modules/logging-release-notes-6-2-12.adoc with bug fix and CVE sections
  • Updated release_notes/logging-release-notes-6.2.adoc to include new module

Fixed Issues

  • LOG-9636: Vector terminationGracePeriodSeconds hardcoded to 10s causes SIGKILL and disk buffer corruption

CVEs Included

  • CVE-2026-25681: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
  • CVE-2026-32281: Go crypto/x509: Denial of Service via inefficient certificate chain validation
  • CVE-2026-32282: Root.Chmod can follow symlinks out of the root
  • CVE-2026-34986: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
  • CVE-2026-39821: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing

Follow-up

Errata number placeholder (RHSA-YYYY:NNNNN) will need to be updated once the actual errata is available.

JIRA: https://redhat.atlassian.net/browse/OBSDOCS-3619

Signed-off-by: John Wilkins jowilkin@redhat.com

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 20, 2026
@openshift-ci openshift-ci Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Jul 20, 2026
- Change 'hardcoded' to 'hard-coded' (Vale RedHat.TermsErrors)
- Replace 'Previously' with 'Before this update'
- Replace 'is granted' passive voice with 'receives' active voice
- Replace 'sufficient' with 'enough' for simpler language

Signed-off-by: John Wilkins <jowilkin@redhat.com>
@ocpdocs-previewbot

ocpdocs-previewbot commented Jul 20, 2026

Copy link
Copy Markdown

🤖 Mon Jul 20 19:05:35 - Prow CI generated the docs preview:

https://115879--ocpdocs-pr.netlify.app/openshift-logging/latest/release_notes/logging-release-notes-6.2.html

The {clo-short} attribute doesn't exist in common-attributes.adoc.
Using {clo} which expands to 'Red Hat OpenShift Logging Operator'.

Signed-off-by: John Wilkins <jowilkin@redhat.com>
@openshift-ci

openshift-ci Bot commented Jul 20, 2026

Copy link
Copy Markdown

@johnwilkins: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants