Your message dated Wed, 29 Jul 2026 10:20:46 +0000
with message-id <[email protected]>
and subject line Bug#1142858: fixed in zaqar 22.0.0-3
has caused the Debian Bug report #1142858,
regarding zaqar: CVE-2026-66139
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142858: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142858
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: zaqar
Version: 22.0.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for zaqar.
CVE-2026-66139[0]:
| OpenStack Zaqar through 22.0.0 allows authentication bypass via an
| EXTRA-SPEC header when a UUID is known.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-66139
https://www.cve.org/CVERecord?id=CVE-2026-66139
[1] https://www.openwall.com/lists/oss-security/2026/07/23/7
[2] https://launchpad.net/bugs/2161254
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: zaqar
Source-Version: 22.0.0-3
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
zaqar, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated zaqar package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 29 Jul 2026 11:18:41 +0200
Source: zaqar
Architecture: source
Version: 22.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1142858
Changes:
zaqar (22.0.0-3) unstable; urgency=high
.
* CVE-2026-66139 / OSSA-2026-029: EXTRA-SPEC header bypasses Keystone
authentication. Applied upstream patch: "Do not bypass authentication for
requests with EXTRA-SPEC header". (Closes: #1142858).
Checksums-Sha1:
a0a7013a09dd516db15ff9f5fda4274ce33f8763 3167 zaqar_22.0.0-3.dsc
d7774ae3ea8543d7a9e779ec2cbbdbedfa7149df 11092 zaqar_22.0.0-3.debian.tar.xz
edc20f62a9d5c1a8b3952019bf7d64c6775e05bd 16743 zaqar_22.0.0-3_amd64.buildinfo
Checksums-Sha256:
5ffd2311d4549b85f15e69d0edbd6247b66d563caebc4a5e18a4a61698bd7c8e 3167
zaqar_22.0.0-3.dsc
d644176f31c081a833e486bbc1f54e936172c1f129420b7d89a73899e78f28d9 11092
zaqar_22.0.0-3.debian.tar.xz
ac813b79b0f281d161dc0394b93ff8eb34de81236f3f7fa29677159dcd701c15 16743
zaqar_22.0.0-3_amd64.buildinfo
Files:
ebcb5221c257869da387a06e42dbc03f 3167 net optional zaqar_22.0.0-3.dsc
07378e92f8ea40c69083563315b467e0 11092 net optional
zaqar_22.0.0-3.debian.tar.xz
13d556f65c04c9deeb7466681cb46b31 16743 net optional
zaqar_22.0.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmppzhsACgkQ1BatFaxr
Q/7LyA//ewfQgxp502k/+bMRH87riQh9dmeeejvLFGVXBLLwXre5f3ksA1lHAwiu
qhFypsjXOqcUnZeuzyaj+ylGQMLjOlqaTx7c5FB6lKX5HwIGBxLU5bJfzwYHOU85
CDQzDP47C75fc7kK+M/skB3lWR2YS4bgp+dx/gqJKXiLGzWnfMtJpkKsYn0TNmEW
MstqM3n20iDb0O4PAK2v2dVvDWxiqDd4vjMV1WBxH5gG3zegWj5bpBeyxBpBwQzy
uJE09iJcmjv1tolE/RvdNJRAu61gpXlZSiXgv2tPogQR01TaTvMN402HKwuty5jK
6TyXphUUKjr1bpfjU1Z7LCpJBMQfoyHNV4bmdi7T8Pr0dN2MlRFdIHNk7RjGhTSt
fzZoGlCiiqU2NxGy8dlI6vLBN+ALjCNEebdv7io8eKIfM0e3znLa6gNdzERs97kj
NKyhqjOiI9zvAYvXQu6bx/del8dWf8VN5SykKaE9lWsRbyVIghDwDmi8nQMIQCJR
T1intNNXNpFPvopmiOfaad1QtTFptqJ0QOfSuTkJL1pWESnWWFIbGg3VCDMMw3DK
Gt20z346VRSiFv3AGj35zjx2l9AJB3pEZfOoGAyjTp5bgu18/rB6WmER3Ra7Mnbi
ZfXuEMDKLbHzcXLanc4vcFbo+lMNWsvyHWkANNPOWifEcbv+rH8=
=EPlX
-----END PGP SIGNATURE-----
pgpr3idUE_plq.pgp
Description: PGP signature
--- End Message ---