Your message dated Wed, 19 Aug 2026 09:34:43 +0000
with message-id <[email protected]>
and subject line Bug#1144814: fixed in octavia 18.0.0-3
has caused the Debian Bug report #1144814,
regarding CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144814: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144814
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: octavia
Version: 16.0.0-2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-035.html
Date:
August 13, 2026
CVE:
CVE-2026-74248
Affects:
Octavia: <16.0.2, ==17.0.0, ==18.0.0
Description:
Chen YuXiang with the Institute of Computing Technology, Chinese Academy of
Sciences, reported a vulnerability in Octavia quality of service (QoS) policy
authorization. By associating another project’s QoS policy with an amphora, an
authenticated user may prevent deletion of that policy. All Octavia deployments
are affected.
Errata:
MITRE assigned CVE-2026-74248 after intial publication.
Patches:
https://review.opendev.org/1000296 (2025.1/epoxy)
https://review.opendev.org/1000295 (2025.2/flamingo)
https://review.opendev.org/1000094 (2026.1/gazpacho)
https://review.opendev.org/998935 (2026.2/hibiscus (development))
Credits:
Chen YuXiang from Institute of Computing Technology, Chinese Academy of
Sciences (CVE-2026-74248)
References:
https://launchpad.net/bugs/2161500
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74248
OSSA History:
2026-08-17 - Errata 1
2026-08-13 - Original Version
--- End Message ---
--- Begin Message ---
Source: octavia
Source-Version: 18.0.0-3
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
octavia, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated octavia package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 19 Aug 2026 11:06:24 +0200
Source: octavia
Architecture: source
Version: 18.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144814
Changes:
octavia (18.0.0-3) unstable; urgency=high
.
* CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock.
Applied upstream patch: "Fix QoS policy validation to use request context".
(Closes: #1144814).
Checksums-Sha1:
06b11d7a3b9ff23640bceec03c32a6f00bab7238 4216 octavia_18.0.0-3.dsc
77f40477eb4e732d1e7caace2b0b8999b5cf2699 21668 octavia_18.0.0-3.debian.tar.xz
0d12af0f49a52dcb3056516124e46077e5e6caf0 20109 octavia_18.0.0-3_amd64.buildinfo
Checksums-Sha256:
0c5eb62fe3f7dee2834e1a03d5a5a59d2603eae8125c3b009be77930886a4675 4216
octavia_18.0.0-3.dsc
fc028dd4553b905699e3d12fed1c75e35c1fd1310eefd99320307a5aa4583d5d 21668
octavia_18.0.0-3.debian.tar.xz
e1f07a0dfc00084eb3ff3f99551cc42d61cc8865bfe393e4ab4b7f23878fcb0b 20109
octavia_18.0.0-3_amd64.buildinfo
Files:
b76838e0484a84a6a237195e7324fb45 4216 net optional octavia_18.0.0-3.dsc
48a512c40982c11533b1a4523a7b5769 21668 net optional
octavia_18.0.0-3.debian.tar.xz
5b1e54d01cd8766ffb4d1efc65638ec0 20109 net optional
octavia_18.0.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqFdKgACgkQ1BatFaxr
Q/6VpBAAjfispCvsYN/D2enY+k+6NNuN4YU1lUQMcxouQXh064usng2PAOSs5PAQ
vgT8vZ6cdOlWkIiwl+w+2z45anhmz4ar1uCW9T6FtLuXF1elw/prBeluaC4Q6ito
AC7189U+yah40hyXrD6e4n5Jb3Oh3LqbEgXW20I9ZXLmM/hQP6hPqqRX2xHYEqjL
nepCOAKFgM4y5xxo9TToBb608Zsg3FSLvwruVFA+DHxfhKOXjEZjxSlxEfpw7YL4
owpMtcSPG8SV2sVAYIYe2aYmJ6UTfJ2v/Ac3+Ob/ZEe+ET4jJgn77zHdxxXKnMX0
sczc++FxffXaVW7n1x0LyNCALlYXUXUYKSacp0FvsLLZr7tGfpxELO3xPY3zEyTA
6ef7V2TI1Cc1xru79XvCgkmSDiq2Sig3ksSkybcHLPvvwHAl6uPHnQIjrcvJiJCo
WS194dlOkUnRNoOuUDeZgO4+kd6gy1HRCeq1XXFtN+8vwhFTSbNsguZp1Gyufy/c
g9qrITosUPefgcGsLd+09G8H2+uI6IzxbjeQUsj60d3OuEci+lKbX8CpbWEsLtM3
X5U6XDKLN1jrWIYOlSx9RINc7p/VMFn+S5H6ICOMotf4qHI0G0mnT9TKBNwDm21q
ZEPjisAK22aZWKRvEMuBfA2z5jIqkW5uGNmYky3n9aASwl495tM=
=GF4S
-----END PGP SIGNATURE-----
pgpBzUeKN8RwF.pgp
Description: PGP signature
--- End Message ---