Your message dated Mon, 24 Aug 2026 22:34:19 +0000
with message-id <[email protected]>
and subject line Bug#1142972: fixed in swift 2.35.1-0+deb13u3
has caused the Debian Bug report #1142972,
regarding swift: CVE-2026-71191 CVE-2026-71192
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142972: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142972
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: swift
Version: 2.35.1-0+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-030.html

:Date: July 28, 2026
:CVE: CVE-2026-pending,
      CVE-2026-pending


Affects
~~~~~~~
- Swift: >=2.18.0 <2.35.4, >=2.36.0 <2.36.3, >=2.37.0 <2.37.3, ==2.38.0


Description
~~~~~~~~~~~
Christian Schwede from NVIDIA reported two authorization bypass
vulnerabilities in Swift's S3API middleware. Insufficient validation of
request headers allows an attacker to copy and read objects belonging to
other tenants. The first issue affects the default ``s3_acl=false``
configuration; the second affects deployments with ``s3_acl=true``. Both
require the attacker to know the target container and object names. All
deployments using the S3API middleware with versions between 2.18.0 and the
fixed releases listed below are affected.



Patches
~~~~~~~
- https://review.opendev.org/998948 (2025.1/epoxy)
- https://review.opendev.org/998949 (2025.1/epoxy)
- https://review.opendev.org/998946 (2025.2/flamingo)
- https://review.opendev.org/998947 (2025.2/flamingo)
- https://review.opendev.org/998944 (2026.1/gazpacho)
- https://review.opendev.org/998945 (2026.1/gazpacho)
- https://review.opendev.org/998942 (2026.2/hibiscus (development))
- https://review.opendev.org/998943 (2026.2/hibiscus (development))


Credits
~~~~~~~
- Christian Schwede from NVIDIA


References
~~~~~~~~~~
- https://launchpad.net/bugs/2158733
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

-- 
Goutham Pacha Ravi
OpenStack Vulnerability Management Team
https://security.openstack.org/vmt.html

--- End Message ---
--- Begin Message ---
Source: swift
Source-Version: 2.35.1-0+deb13u3
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
swift, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated swift package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 17 Aug 2026 11:01:41 +0200
Source: swift
Architecture: source
Version: 2.35.1-0+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1140678 1142972 1142973
Changes:
 swift (2.35.1-0+deb13u3) trixie-security; urgency=medium
 .
   * CVE-2026-71191 / OSSA-2026-030: Swift S3API header authorization bypass.
     Applied upstream patch:
     - "s3api: require signing of sensitive SigV4 x-amz headers"
     - "s3api: drop native Swift control headers from client requests"
     (Closes: #1142972).
   * CVE-2026-71192 / OSSA-2026-031: proxy denial of service via Accept header.
     Applied upstream patch:
     - "swob: avoid excessive backtracking in Accept parser"
     (Closes: #1142973).
   * CVE-2026-50221: Swift proxy-server SSRF via internal update header
     injection: applied upstream patch: Block internal update headers at the
     gatekeeper (Closes: #1140678).
Checksums-Sha1:
 1e47d7458955ec21348b403ee58c641d130fef46 3165 swift_2.35.1-0+deb13u3.dsc
 5dc7039ecfd608a05ec987bfe49cc2fb6f587148 2706568 swift_2.35.1.orig.tar.xz
 ae854c83db3f911d226f3887298bab6765f74d58 38196 
swift_2.35.1-0+deb13u3.debian.tar.xz
 223f79ebb4a2c3b64035c335a7dd7e8a155dfa3d 14846 
swift_2.35.1-0+deb13u3_amd64.buildinfo
Checksums-Sha256:
 6730cd82004b325f2452fd3297d93e31676cb9f6fd0911e8df288590d4bc64cb 3165 
swift_2.35.1-0+deb13u3.dsc
 ee2bba0d77ce5bccc04db93d531ddd65ee092a1ce1070b0995f1ca8f7a3a5beb 2706568 
swift_2.35.1.orig.tar.xz
 89a1262a296f09c1816ef76b9348e08989b5e6b823abe760dbdf54a6a1e84096 38196 
swift_2.35.1-0+deb13u3.debian.tar.xz
 6e3d18523197fcd2c7b15e4c82efc20d4cec390485e114b811586affedcd2944 14846 
swift_2.35.1-0+deb13u3_amd64.buildinfo
Files:
 65ee8fbc7f3cb844f495dd8a5688fcf1 3165 net optional swift_2.35.1-0+deb13u3.dsc
 0fe9e0f72d050292fb9182633c9462af 2706568 net optional swift_2.35.1.orig.tar.xz
 f5600cd5a7861182df88df01583dee0e 38196 net optional 
swift_2.35.1-0+deb13u3.debian.tar.xz
 3293c3cbcfa68c3fe971b41684523cb7 14846 net optional 
swift_2.35.1-0+deb13u3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqEFn0ACgkQ1BatFaxr
Q/6TuxAAgSko0IqFQmIwH6feQEEhUdZlfhz3u4vllnabHtb1ZhuF5QGRHR+cVmi4
DHYQJPJii72AKRRQetmRjrXW4offcb78wl4chyz0cOGoF95joLrcJkqtB1MXlun9
+o2W/GI6MByIl9mWdXnVWmrz/VRI00ToMmg6WkOwDnxi1LFvKBBC4QmGg+ONvnpI
vidMwwD2SuH/unVjpmlFkoFUCkjBVo6UFB+f4zII9mKUrf0aWgSJsWh6XjPV/0dI
/51KywAsVtPBF9hCNwvYmhlcnqNeS28zusMXjiNXa6YPzQKhSvYC4/IwWC7kaCnf
ukyVJj3wLNOY5xsQgV14URymS4lixA7Sgn2EhdHZP/nvkfL+/eNO7r2+EEcNTcVp
NG+etV7acgYulYq/udbZ8y9SkeCzR+5QdJDRfVF50i6Ocbv+Ef9YB46zIzSXF/vV
dMrqYsNhd4cqspoDFiFXzDDZarJmIIEpg1pV+jAOMlOSQmifwB0GP8qp2E+eMe2b
M/54qgO8QU13LsbT4fXlRgIJJZmC59Bs2xrdicAJM24I+ZziSNnKOaTcnnC6TYgk
21O5x4qMyCMOYurfNsCqed3PGe9kEI+QmSPqlTq5IjdCGXfw8Axr0VOv5Vaz3xy6
B1US0F+qaH0D8L9Mxlib6nTakcDFrxlSFHe0mBjvAKf92Qp/2TA=
=0nDe
-----END PGP SIGNATURE-----

Attachment: pgpUf4JMxnIWG.pgp
Description: PGP signature


--- End Message ---

Reply via email to