It seems reasonable to go forward with the OSSN worded to assume there is no fix forthcoming. Then once there's an actual fix merged to stable branches we can follow up with an OSSA (though worth keeping in mind the proposed backport, as far as I understand, only solves the problem for tokens revoked after the patch gets applied, not any which predate its application).
It seems reasonable to go forward with the OSSN worded to assume there is no fix forthcoming. Then once there's an actual fix merged to stable branches we can follow up with an OSSA (though worth keeping in mind the proposed backport, as far as I understand, only solves the problem for tokens revoked after the patch gets applied, not any which predate its application).