ironic (1:35.0.1-8)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/openstack-team/services/ironic.git
-
- Branch: debian/gazpacho
- Path: debian/changelog
- Repo size: 16064512
- Browser: https://salsa.debian.org/openstack-team/services/ironic
- Last scan: 2026-07-09 14:31:23+00
- Next scan: 2026-07-18 11:10:00+00
- Merge requests: 1
- CI pipeline status: failed
- Debian changelog in Git:
ironic (1:35.0.1-8) unstable; urgency=high
* CVE-2026-44918: multiple related vulnerabilities in Ironic RBAC. An
authenticated project manager can change the node associated with Volume
Connectors or Volume Target objects, potentially changing the project
permitted to access the object. Volume Connectors contain secrets in
environments configuring boot from volume with iSCSI volumes. Applied
upstream patch: "Prevent rehoming resources to nodes with different owner".
(Closes: #1141716).
* CVE-2026-54423: A malicious user with access to deploy a node directly via
Ironic can specify the IPMI `send_raw` deployment step with a malicious
payload and send commands to that nodes' BMC. Applied upstream patches:
- Add operator-configurable step disallow lists
- block vendor.send_raw
(Closes: #1141717).
-- Thomas Goirand <zigo@debian.org> Fri, 26 Jun 2026 11:18:54 +0200
- This branch is even with tag debian/35.0.1-8