[Git][security-tracker-team/security-tracker][master] ironic DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 17 19:52:13 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a466cde7 by Moritz Mühlenhoff at 2026-08-17T20:51:35+02:00
ironic DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -7898,6 +7898,7 @@ CVE-2026-68969 (Apache Airflow wrote Variable values and Connection `extra` cont
 	- airflow <itp> (bug #819700)
 CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require network-level access controls]
 	- ironic 1:35.0.1-10 (bug #1144214)
+	[trixie] - ironic 1:29.0.5-0+deb13u3
 	[bookworm] - ironic 1:21.4.4-0+deb12u2
 	NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0106
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162821
@@ -40605,11 +40606,9 @@ CVE-2026-57825
 	NOTE: Fixed by: https://github.com/ocaml/opam/commit/175a5d777806ad32fa6cdd95f2501dc4bd5e584e (2.5.2)
 CVE-2026-44918 (OpenStack Ironic through before 37.0.1 allows creation or modification ...)
 	- ironic 1:35.0.1-8 (bug #1141716)
-	[trixie] - ironic <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-026.html
 CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the ability to  ...)
 	- ironic 1:35.0.1-8 (bug #1141717)
-	[trixie] - ironic <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
 CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
 	- qemu 1:11.0.0+ds-1
@@ -59689,7 +59688,6 @@ CVE-2026-XXXX [RUSTSEC-2026-0176]
 CVE-2026-54421 (In OpenStack Ironic before 37.0.1, when applying a PATCH to update fie ...)
 	{DLA-4743-1}
 	- ironic 1:35.0.1-6 (bug #1140012)
-	[trixie] - ironic <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155049
 CVE-2026-54420 (LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM  ...)
 	NOT-FOR-US: LiteSpeed cPanel plugin
@@ -90067,7 +90065,6 @@ CVE-2026-43504 (An issue was discovered in Prosody before 0.12.6 and 1.0.0 throu
 CVE-2026-43003 (An issue was discovered in OpenStack ironic-python-agent 1.0.0 through ...)
 	{DLA-4743-1}
 	- ironic 1:35.0.1-7 (bug #1140187)
-	[trixie] - ironic <no-dsa> (Minor issue)
 	- ironic-python-agent 11.5.0-3 (bug #1135646)
 	[trixie] - ironic-python-agent <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2148310


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Aug 2026] DSA-6445-1 ironic - security update
+	{CVE-2026-43003 CVE-2026-44918 CVE-2026-54421 CVE-2026-54423}
+	[trixie] - ironic 1:29.0.5-0+deb13u3
 [16 Aug 2026] DSA-6444-1 neutron - security update
 	{CVE-2026-55707}
 	[trixie] - neutron 2:26.0.3-0+deb13u3


=====================================
data/dsa-needed.txt
=====================================
@@ -49,8 +49,6 @@ gimp
 --
 gst-plugins-bad1.0 (jmm)
 --
-ironic
---
 jackson-databind
 --
 jetty9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a466cde72adc5cb803307ab1650025364c708c07

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a466cde72adc5cb803307ab1650025364c708c07
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/827fb93e/attachment.htm>


More information about the debian-security-tracker-commits mailing list