Your message dated Tue, 28 Jul 2026 13:51:57 +0000
with message-id <[email protected]>
and subject line Bug#1142943: fixed in ironic-python-agent 11.5.0-4
has caused the Debian Bug report #1142943,
regarding CVE-2026-54422: credential extraction via malicious container
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142943: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142943
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ironic-python-agent
Version: 10.2.0-3
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce:


=====================================================================================
OSSA-2026-028: Credential extraction from Ironic Python Agent via malicious 
container
=====================================================================================

:Date: July 23, 2026
:CVE: CVE-2026-54422


Affects
~~~~~~~
- Ironic-python-agent: >=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1


Description
~~~~~~~~~~~
Yuliang Xiao reported a vulnerability in Ironic Python Agent's bootc
container deployment support. A malicious container can extract the
secrets used to fetch from the OCI registry on deployment.

Operators can fix this issue by applying the provided patches or completely
disabling the bootc deploy_interface on their Ironic conductors.

Any Ironic user with the ability to deploy arbitrary containers from the
bootc deploy_interface can exploit this.


Patches
~~~~~~~
- https://review.opendev.org/998479 (2026.2/hibiscus (development))
- https://review.opendev.org/998481 (2026.1/gazpacho)
- https://review.opendev.org/998484 (2025.2/flamingo)
- https://review.opendev.org/998485 (2025.1/epoxy)
- https://review.opendev.org/998480 (bugfix/11.6)
- https://review.opendev.org/998493 (bugfix/11.4)
- https://review.opendev.org/998494 (bugfix/11.3)


Credits
~~~~~~~
- Yuliang Xiao


References
~~~~~~~~~~
- https://launchpad.net/bugs/2155826
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54422


Notes
~~~~~
- Ironic Python Agent bugfix branch patches will be available in git for
  interested operators. We will not perform an additional release from
  these branches.

-- 
Goutham Pacha Ravi
OpenStack Vulnerability Management Team
https://security.openstack.org/vmt.html

--- End Message ---
--- Begin Message ---
Source: ironic-python-agent
Source-Version: 11.5.0-4
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
ironic-python-agent, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated ironic-python-agent 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 28 Jul 2026 15:16:29 +0200
Source: ironic-python-agent
Architecture: source
Version: 11.5.0-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1142857 1142943
Changes:
 ironic-python-agent (11.5.0-4) unstable; urgency=medium
 .
   * CVE-2026-66138 / OSSA-2026-027: command execution via unsanitized config.
     Applied upstream patch: "fix NTP command handling" (Closes: #1142857).
   * CVE-2026-54422 / OSSA-2026-028: credential extraction from Ironic Python
     Agent via malicious container. Applied upstream patch: "Do not expose
     registry pull secret to bootc container" (Closes: #1142943).
Checksums-Sha1:
 fd5c9baa04cb6a82e8d7684350df8338e967d5a0 2661 ironic-python-agent_11.5.0-4.dsc
 98cac752aef71d46cb227187b35bdd3545e46deb 14028 
ironic-python-agent_11.5.0-4.debian.tar.xz
 22fa46a3965266fcf692a135dbfc98ddd939408b 12539 
ironic-python-agent_11.5.0-4_amd64.buildinfo
Checksums-Sha256:
 1a5e506fd4bc43adef973f27b66cfee540b29fcf94d3527272cbf49c64fb592d 2661 
ironic-python-agent_11.5.0-4.dsc
 9d6d64f5d58a0b4ebc6ae957b1c10dd30c3589396144d5ae97a9d07bb27399e1 14028 
ironic-python-agent_11.5.0-4.debian.tar.xz
 97c5fed57794a146afc4776cd8090c5b01bab28121d35f55a7314b278471f9a2 12539 
ironic-python-agent_11.5.0-4_amd64.buildinfo
Files:
 a9ed002b92054020aaa5538af931f608 2661 net optional 
ironic-python-agent_11.5.0-4.dsc
 6e66c013fba09ea450a1a354d71e59ce 14028 net optional 
ironic-python-agent_11.5.0-4.debian.tar.xz
 0048c2b5716afaa51ee1f3db008186ab 12539 net optional 
ironic-python-agent_11.5.0-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmposSQACgkQ1BatFaxr
Q/4XUQ//aYH6iIoP84TU184FEhuFIeyBVQ2aCbjjnwMCKNGISYHtw05LisuVFbZY
GXOmm5suq93iPI39QvKY6dfP9CrEWyl8jzTn/9FkdpUvJYTdnx9R0oCQLd/1zAm4
V1uN9X4CyNExfmykV8v6aC8VlWIpo5Gz2HVcn+tV8Tc8AVGQ0B+OOel60QLTICCf
31pmQfu5Orbi7gyzvTwY11CuAkxK+zDbBWO6XSfsU3RxDIms/AsEb0hMc8Ak1YFi
/Eihs3BSk+r1Weox0BebdVLSUhKRyqaSOaW9DHSPLD1KI0vQjzSAMoV5Kvmj/eWS
ZrBOfhxvHApee5rxiyF2VPUuMZNPNr1xeJ9oXwrsI2SXkOJU2TdqdY6Nn32IjYuO
Qha9A0lMKmf9AErW006YwXb7wgaoVsnGJEjaOBBWQMCGdTtvmV3Up1ZHGvMwtbFQ
ssdM0W/SSYjRSYciLRWtGQHCWlvrsGFd7+ppqucevMz5MjqWsc+po6OfZ/eOM3hF
wr+eqTw1ursIKTeTipU+trCJblJzzxk3wdKigcWOli9tL5Lj725t26IB5dMY31dW
W5VnTOk5YGmiqYOo1dGVqrEOafu+g9vTTdjzkEiO2NRPT+97bXZU7TmfvJ8NtViB
ZPDvI1jQov9Ap64c4pJZV3Fp8IUY+Q6k2nausIWuS8/sXPy2Ig0=
=hddu
-----END PGP SIGNATURE-----

Attachment: pgphcKWdcjFlD.pgp
Description: PGP signature


--- End Message ---

Reply via email to