[Git][security-tracker-team/security-tracker][master] ironic DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 17 19:52:13 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a466cde7 by Moritz Mühlenhoff at 2026-08-17T20:51:35+02:00
ironic DSA
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -7898,6 +7898,7 @@ CVE-2026-68969 (Apache Airflow wrote Variable values and Connection `extra` cont
- airflow <itp> (bug #819700)
CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access controls]
- ironic 1:35.0.1-10 (bug #1144214)
+ [trixie] - ironic 1:29.0.5-0+deb13u3
[bookworm] - ironic 1:21.4.4-0+deb12u2
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
NOTE: https://bugs.launchpad.net/ironic/+bug/2162821
@@ -40605,11 +40606,9 @@ CVE-2026-57825
NOTE: Fixed by: https://github.com/ocaml/opam/commit/175a5d777806ad32fa6cdd95f2501dc4bd5e584e (2.5.2)
CVE-2026-44918 (OpenStack Ironic through before 37.0.1 allows creation or modification ...)
- ironic 1:35.0.1-8 (bug #1141716)
- [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-026.html
CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the ability to ...)
- ironic 1:35.0.1-8 (bug #1141717)
- [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
- qemu 1:11.0.0+ds-1
@@ -59689,7 +59688,6 @@ CVE-2026-XXXX [RUSTSEC-2026-0176]
CVE-2026-54421 (In OpenStack Ironic before 37.0.1, when applying a PATCH to update fie ...)
{DLA-4743-1}
- ironic 1:35.0.1-6 (bug #1140012)
- [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2155049
CVE-2026-54420 (LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM ...)
NOT-FOR-US: LiteSpeed cPanel plugin
@@ -90067,7 +90065,6 @@ CVE-2026-43504 (An issue was discovered in Prosody before 0.12.6 and 1.0.0 throu
CVE-2026-43003 (An issue was discovered in OpenStack ironic-python-agent 1.0.0 through ...)
{DLA-4743-1}
- ironic 1:35.0.1-7 (bug #1140187)
- [trixie] - ironic <no-dsa> (Minor issue)
- ironic-python-agent 11.5.0-3 (bug #1135646)
[trixie] - ironic-python-agent <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2148310
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Aug 2026] DSA-6445-1 ironic - security update
+ {CVE-2026-43003 CVE-2026-44918 CVE-2026-54421 CVE-2026-54423}
+ [trixie] - ironic 1:29.0.5-0+deb13u3
[16 Aug 2026] DSA-6444-1 neutron - security update
{CVE-2026-55707}
[trixie] - neutron 2:26.0.3-0+deb13u3
=====================================
data/dsa-needed.txt
=====================================
@@ -49,8 +49,6 @@ gimp
--
gst-plugins-bad1.0 (jmm)
--
-ironic
---
jackson-databind
--
jetty9
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a466cde72adc5cb803307ab1650025364c708c07
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a466cde72adc5cb803307ab1650025364c708c07
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/827fb93e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list