-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 16 Jun 2026 12:46:11 +0200
Source: ironic
Architecture: source
Version: 1:29.0.5-0+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1140012 1140187 1141716 1141717 1144214
Changes:
 ironic (1:29.0.5-0+deb13u3) trixie-security; urgency=medium
 .
   * Add follow-up patch for CVE-2026-46447 (erata1): "Fix kernel parameter
     parsing for quoted values and whitespace".
   * CVE-2026-54421: Sensitive properties returned unredacted in POST and PATCH
     HTTP responses. Added upstream patch: "Fix sensitive properties returned on
     volume targets" (Closes: #1140012).
   * CVE-2026-43003 / OSSN-2026-0100: Command injection via chroot execution of
     tenant-controlled binaries. Added upstream patch: "Add an agent flag to
     disable installing boatloaders" (Closes: #1140187).
   * CVE-2026-44918: multiple related vulnerabilities in Ironic RBAC. An
     authenticated project manager can change the node associated with Volume
     Connectors or Volume Target objects, potentially changing the project
     permitted to access the object. Volume Connectors contain secrets in
     environments configuring boot from volume with iSCSI volumes. Applied
     upstream patch: "Prevent rehoming resources to nodes with different owner".
     (Closes: #1141716).
   * CVE-2026-54423: A malicious user with access to deploy a node directly via
     Ironic can specify the IPMI `send_raw` deployment step with a malicious
     payload and send commands to that nodes' BMC. Applied upstream patches:
     - Add operator-configurable step disallow lists
     - block vendor.send_raw
     (Closes: #1141717).
   * OSSN-0106: API ramdisk endpoints require network-level access controls.
     Added upstream patch: "Add [api] enable_ramdisk_endpoints config option"
     (Closes: #1144214).
Checksums-Sha1:
 da04dddc75a899b7899e72128223af1cb4e9b08a 4096 ironic_29.0.5-0+deb13u3.dsc
 b6b17bf8a174467edda78a62b7136c12b4058129 1892376 ironic_29.0.5.orig.tar.xz
 290b0c28884154dbd452f03ee1e0ed2ea41cb980 76328 
ironic_29.0.5-0+deb13u3.debian.tar.xz
 f4c574d4cb4be5f29c5543190ca5efc849b5f746 23072 
ironic_29.0.5-0+deb13u3_amd64.buildinfo
Checksums-Sha256:
 68cf74aa60d9b886b0cd81e61c4f634cbd677f4014f98fb4df03545cf8cace41 4096 
ironic_29.0.5-0+deb13u3.dsc
 8381a472d7d79dc798a74917bf1cb8eb7795916d952643b64c7f5dc50532e6d9 1892376 
ironic_29.0.5.orig.tar.xz
 ebc098aa465aa552e42144c2b3134dec8a8e491a3af983d95e4dd38a4e93c8f7 76328 
ironic_29.0.5-0+deb13u3.debian.tar.xz
 0c648c96ed0e3b334ab24658e5cb6a40e010831d15d710219d8c75a24954df46 23072 
ironic_29.0.5-0+deb13u3_amd64.buildinfo
Files:
 857093036c659e8b533dadf7399c72e3 4096 net optional ironic_29.0.5-0+deb13u3.dsc
 52695995363316a16620272afa449301 1892376 net optional ironic_29.0.5.orig.tar.xz
 2d02b9797312893595b67dd8290d0748 76328 net optional 
ironic_29.0.5-0+deb13u3.debian.tar.xz
 5111e6499f4f44baa8153842e39e614b 23072 net optional 
ironic_29.0.5-0+deb13u3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqBn0kACgkQ1BatFaxr
Q/7UmxAAh0C5SnyoEzIPU7bvgNOphwMIdi+FWMjZGljM9lVkezrYkIt9vUypnB3m
7+FrFDnZhMvYzqMkSB7vOPtYby1NlOXggrfbgzTQnPb8PtRh7QdpBeze4kgOpdZY
9T1XKdan8TSOfGiqb+3SlszazvyHHSnx8w3ojjeVGhzRvmJZR8+VzyhFZVBHKyvO
jRZOkMgj01hnj+rqGqOzYph9eqo30tLqsJNvjb5roDmA1fwfsnnB3OFtG8HgXvrH
0Ox4HB4uG+Lh+LBEwWg93RLrHs9PAS5GRCV2xbddqoMLVddmfZDqmF5ZoX6OBgO1
2S02mfe2jHEVV/UUM9p+k2urr3JaDkUuEjBXyOaonLmysw5WmOghl1C6jNYht/g2
sj3rMZ6wVGV/hOyS0gatO94zDB1cW7Onx+HRx7+z/OBU+X32lDRpBFnlgPyDgRe3
P1PsK/McRDeXOWV7gCkVlm4Ogdm8IsZD7/ytoc+41I7sIOwYoICIpyDpK+XDUHX/
3m1UveFp0tRl23OPFbT7b6o3VITyx5Nu0uVvtkYS/3AZdujykDcXsIk2RTdfCVQL
W7eyv46AY/B8notOINZoFlQP2tZFdYQg2R+m1zqV+aqTOmFbCQXxhGVWjwZkxhMw
ol8HOYb9uVdFZdJuOGtqK2kwbtPW80zFlDaVHau2L5o7f7B4PJs=
=wPe8
-----END PGP SIGNATURE-----

Attachment: pgpZvDuyDZlVo.pgp
Description: PGP signature

Reply via email to