Your message dated Thu, 17 Sep 2026 21:06:54 +0000
with message-id <[email protected]>
and subject line Bug#1148175: fixed in octavia 18.0.0-4
has caused the Debian Bug report #1148175,
regarding Command Injection (RCE) on Octavia amphora via API
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1148175: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148175
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: octavia
Severity: serious

This has been reported on Launchpad here:

https://bugs.launchpad.net/octavia/+bug/2162101

and here:
https://bugs.launchpad.net/octavia/+bug/2162103

though the author probably haven't realized how grave the bug was.
In fact, we're talking about an RCE, since it's possible inject any type
of command into Haproxy.

The fixes are here:
https://review.opendev.org/q/Ia6affaafcaa8b22ec2e0c94b3c4007cccaae41ba
and here:
https://review.opendev.org/q/I23c3ca392233c7e8223a9a00b9ee07c6f4b63615

I'll backport these patches to all the versions of OpenStack I still support,
meaning from Bookworm (zed) to Unstable (Gazpacho).

Cheers,

Thomas Goirand (zigo)

--- End Message ---
--- Begin Message ---
Source: octavia
Source-Version: 18.0.0-4
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
octavia, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated octavia package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 17 Sep 2026 22:04:33 +0200
Source: octavia
Architecture: source
Version: 18.0.0-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1148175
Changes:
 octavia (18.0.0-4) unstable; urgency=medium
 .
   * Update debian/salsa-ci.yml.
   * Octavia is vulnerable to an RCE in its amphora via the Octavia API.
     Added upstream patches (Closes: #1148175):
     - Fix_HAProxy_config_injection_via_tls_ciphers_field.patch
     - Fix_HAProxy_config_injection_via_L7_policy_redirect_URLs.patch
   * Cleans better.
Checksums-Sha1:
 c8c75037c3aed54c8ad8ae58a27fa60480331698 4216 octavia_18.0.0-4.dsc
 1b428575830035688a16261b87ce642bb6c9dd1a 25212 octavia_18.0.0-4.debian.tar.xz
 b5c3a534681357ff413f36ebb80e38cca9f0c3a4 19860 octavia_18.0.0-4_amd64.buildinfo
Checksums-Sha256:
 6d5d3d9a5760c209427e60ec82ace9c9894dc161cd7d0f353de7f04886244023 4216 
octavia_18.0.0-4.dsc
 35ee86c6c9f4d3bc145bd29b03cd9ecb3393396fd238c396bf00f2893bc7cff9 25212 
octavia_18.0.0-4.debian.tar.xz
 7ab8d49720540a94b27d618c2a620c5f18197b41fedcf9028778ee9dc285ccd9 19860 
octavia_18.0.0-4_amd64.buildinfo
Files:
 0c0736c03754a27311e6359f11b6a681 4216 net optional octavia_18.0.0-4.dsc
 9669501a86fddf407a3cf4b2d7d45568 25212 net optional 
octavia_18.0.0-4.debian.tar.xz
 b256a62aadabbd2e003cc52c7355a43a 19860 net optional 
octavia_18.0.0-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqsUXIACgkQ1BatFaxr
Q/4rmA/8CJ3Aoj7ByOyBG/tJShkPPVkjl5G+hSnFOHCjtohPK/AtXoH388px3QAM
1VuhxXQpXrFxpIYoz3S9R8QZ2BsCzAAY8L5ybj3F7XKBvEAOZdYA5ZPWGpgDMyHM
E4ji7IDZ/UUG8KpjV6oaNPqD0bZZna4hMzI3By0lHqrDFP1WG+y8ltxX41ooenhy
RZaiXVnZ2T3e/fexTCSbTNe+8ERwuWEe70Ze2zGnvcz8qzL6pwuk9hoXWGMLdCio
nFOCjpmL5dBOMkgd3kDFEm5mgdl3MJP1AMmoOcoE0iVuKg6LFNF+FAnUw5rWy+LM
9BtJyXc1CSyy8TrrUqQP565HmC87hn+YBGvIWrI4QFcIYdXXhR3+u2ajLfinWlIH
iIsZ1yqgo3b0np2nE8cwnitX44h+uU/r12MphmO4XwHnHWDiXCk17hGspTcr/Eta
wFgeooHS7kH7ohCjaLWrzwHraTYxDIpePe61ukyMDO05vzyn/ehhNBotrLl9C/lU
u+6x2vRvp5Q43pXDSJ89n84BlneUm3uoBw9wTBYWqpBbf6jkjRPB/sFodYsXgHTL
OZiCwS04tOyMP3ienAUQk4bzOfoj3B04/YGNHUcI7J2PstyerOr+L/3cGvynSNva
ja5g8zH8lRdcPrtDb2qcsKqi2ipwy8+WRy7HqIDQKu5FuEGa66Q=
=FkLh
-----END PGP SIGNATURE-----

Attachment: pgp7kXBBHHtvu.pgp
Description: PGP signature


--- End Message ---

Reply via email to