Your message dated Thu, 06 Aug 2026 10:20:28 +0000
with message-id <[email protected]>
and subject line Bug#1143790: fixed in ironic 1:35.0.1-9
has caused the Debian Bug report #1143790,
regarding CVE-2026-71201 / OSSA-2026-033: Portgroup shard filter bypasses
project scope
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143790: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143790
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ironic
Version: 1:29.0.5-0+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-033.html
Date: August 05, 2026
CVE: CVE-2026-71201
Affects: Ironic: >=34.0.0 <35.0.2, >=36.0.0 <38.0.1
Description:
Chen YuXiang of Institute of Computing Technology, Chinese Academy of
Sciences reported an issue in Ironic’s API. When a project reader
requests a list of portgroups filtered by shard, all portgroups in that
shard are returned, not just those in their project.
This is a similar vulnerability to the one originally advisoried in
OSSA-2026-026 – that issue impacted ports; this impacts portgroups.
Patches:
https://review.opendev.org/999762 (2026.1/gazpacho)
https://review.opendev.org/999656 (2026.2/hibiscus (development))
https://review.opendev.org/999765 (Bugfix/34.0)
https://review.opendev.org/999764 (Bugfix/37.0)
https://review.opendev.org/999763 (Bugfix/38.0)
Credits
Chen YuXiang from Institute of Computing Technology, Chinese
Academy of Sciences
References:
https://launchpad.net/bugs/2162715
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71201
Notes:
Ironic bugfix branch patches will be available in git for interested
operators. We will not perform an additional release from these
branches.
--- End Message ---
--- Begin Message ---
Source: ironic
Source-Version: 1:35.0.1-9
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ironic, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated ironic package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 06 Aug 2026 11:30:51 +0200
Source: ironic
Architecture: source
Version: 1:35.0.1-9
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1143790
Changes:
ironic (1:35.0.1-9) unstable; urgency=medium
.
* CVE-2026-71201 / OSSA-2026-033: Portgroup shard filter bypasses project
scope. Applied upstream patch: "Portgroup shard filter bypasses scope to
project" (Closes: #1143790).
Checksums-Sha1:
ad539a1feaee71166f7c5b35303243eddd2b0e2a 4063 ironic_35.0.1-9.dsc
616d4159d35eb9dd399235d451083c0df9471c6a 61800 ironic_35.0.1-9.debian.tar.xz
9449ee26da03370a94ea2238491fbcad550cf9e2 22523 ironic_35.0.1-9_amd64.buildinfo
Checksums-Sha256:
9432eb28628e9d1636a9681d2abea7b04712bc2c9a26d3c1f79974b243e25def 4063
ironic_35.0.1-9.dsc
f0067af7cb777ca68d350f2bf025e0636493e8084ab9dcec5fc39d83ac45fe97 61800
ironic_35.0.1-9.debian.tar.xz
ea12457fbd31ddfe82765c803478e5b12ada8f4834f8888b37b6705d584d0f8b 22523
ironic_35.0.1-9_amd64.buildinfo
Files:
2a4f7a91ec0f7d36390b99348470c06d 4063 net optional ironic_35.0.1-9.dsc
09a7c52b2570bca906135c3da4aeda76 61800 net optional
ironic_35.0.1-9.debian.tar.xz
ae9c838985109f05e89155ab85fa89db 22523 net optional
ironic_35.0.1-9_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmp0WUQACgkQ1BatFaxr
Q/6E7Q/7BAOuyskwMit4LdEmt3Ygh+atmjoCwf7cezQ1BcBJ4oq2sySr3jt/uhX4
aUdfB1zD64fhr9qdk4d8xBBfZmGtDJNzP+vQe0zzqEngHGDoIAaWaL2POGSffQC0
jNzCKPSpsxhK70Ospf4o1UuG8BYKraIkSJDLmvotkCldXaPodFLez4DxWTudJyBd
wmjlceOusp29FMoYzwRFWQy4j2zaIpTwuuCTsdypl8YNJegU83VPLUc+OjNBhmon
jYv877nvKlh7KGNUHjMoG+jzDjX3nk8KR1PXcJGIBc9JInrg7lXoxh/4kzmn5Ada
350/jm49QH+Uo/A3S40V5WxA8xwCiu6A5GyJbnZ8Vqf/M5vTs09itQs0ergbZr7p
eODIXVBueGLNdVGgubpnheaL3XsYBbCVPP9WNx+6KjcZ/FG1/ClGW5WRMRGOpsuu
D7aSDmr4Xevfjb6ibreWuSKUQex90DSv6RfGGZdcr0GA3jmrIXJtuJwq0ychuh94
/csOd/ksy3TsL6Z9ZtPHGMvuZ6Ws/Hj4oqEN7oYhkM+QS/K0+I62TOVuUJs4WOAU
izgrI6uUJcIdIsSHBeRpfu9zLfKk7FWBkl15aYVY9PMLaCRxj9MJ5CW2kqmjLcyr
wRuNEGub5XlXGpalqlIQaDPNr8sw3/G1GU8wBQ2ZOT1DulxEltA=
=Djsm
-----END PGP SIGNATURE-----
pgp0ThZFruCfO.pgp
Description: PGP signature
--- End Message ---