[Git][security-tracker-team/security-tracker][master] Cleanup in inersections of various ironic updates (both via DSA and pu)
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 10 19:34:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d8e39022 by Salvatore Bonaccorso at 2026-07-10T20:33:40+02:00
Cleanup in inersections of various ironic updates (both via DSA and pu)
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/next-oldstable-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -39347,8 +39347,9 @@ CVE-2026-45033 (GitHub Copilot CLI brings AI-powered coding assistance directly
CVE-2026-45028 (Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM ...)
NOT-FOR-US: Astro
CVE-2026-44919 (In OpenStack Ironic through 35.x before a3f6d73, during image handling ...)
- {DSA-6341-1}
- ironic 1:35.0.1-3 (bug #1136655)
+ [trixie] - ironic 1:29.0.5-0+deb13u1
+ [bookworm] - ironic 1:21.4.4-0+deb12u1
[bullseye] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2150332
NOTE: https://opendev.org/openstack/ironic/commit/a3f6d735ac3642ab95b49142c7305f072ae748d0
@@ -44322,8 +44323,9 @@ CVE-2026-6411 (This vulnerability, in the MAXHUB Pivot client application versio
CVE-2026-4935 (The OttoKit: All-in-One Automation Platform WordPress plugin before 1. ...)
NOT-FOR-US: WordPress plugin
CVE-2026-44916 (In OpenStack Ironic before 35.0.2 (in a certain non-default configurat ...)
- {DSA-6341-1}
- ironic 1:35.0.1-2 (bug #1136005)
+ [trixie] - ironic 1:29.0.5-0+deb13u1
+ [bookworm] - ironic 1:21.1.0-3+deb12u1
[bullseye] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2148307
NOTE: https://review.opendev.org/c/openstack/ironic/+/987514
@@ -47288,8 +47290,9 @@ CVE-2026-43002 (An issue was discovered in OpenStack Horizon 25.6 and 25.7 befor
NOTE: https://www.openwall.com/lists/oss-security/2026/05/05/7
NOTE: https://bugs.launchpad.net/horizon/+bug/2150331
CVE-2026-42997 (An issue was discovered in idrac in OpenStack Ironic before 35.0.1. Du ...)
- {DSA-6341-1}
- ironic 1:35.0.1-1 (bug #1135811)
+ [trixie] - ironic 1:29.0.5-0+deb13u1
+ [bookworm] - ironic 1:21.1.0-3+deb12u1
[bullseye] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2148317
NOTE: https://www.openwall.com/lists/oss-security/2026/05/05/10
@@ -51325,9 +51328,9 @@ CVE-2026-5362 (An authenticated attacker with permission to edit document conten
CVE-2026-5306 (The Check & Log Email WordPress plugin before 2.0.13 does not properl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-42510 (OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-defa ...)
- {DSA-6341-1}
- ironic 1:35.0.1-1 (bug #1135255)
- [bookworm] - ironic <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - ironic 1:29.0.5-0+deb13u1
+ [bookworm] - ironic 1:21.1.0-3+deb12u1
[bullseye] - ironic <postponed> (Minor issue; can be fixed in next update)
NOTE: https://bugs.launchpad.net/ironic/+bug/2148331
CVE-2026-41372 (OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hos ...)
@@ -188411,7 +188414,7 @@ CVE-2025-44023 (An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212
NOT-FOR-US: D-Link
CVE-2025-44021 (OpenStack Ironic before 29.0.1 can write unintended files to a target ...)
- ironic 1:29.0.0-6 (bug #1104964)
- [bookworm] - ironic <no-dsa> (Minor issue)
+ [bookworm] - ironic 1:21.1.0-3+deb12u1
[bullseye] - ironic <postponed> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2107847
NOTE: https://security.openstack.org/ossa/OSSA-2025-001.html
@@ -264323,8 +264326,8 @@ CVE-2024-20440 (A vulnerability in Cisco Smart Licensing Utility could allow an
CVE-2024-20439 (A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an ...)
NOT-FOR-US: Cisco
CVE-2024-44082 (In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13. ...)
- {DSA-6341-1}
- ironic 1:26.1.0-1
+ [bookworm] - ironic 1:21.4.4-0+deb12u1
[bullseye] - ironic <postponed> (Minor issue; can be fixed in next update)
- ironic-python-agent 9.14.0-1
NOTE: https://www.openwall.com/lists/oss-security/2024/09/04/4
=====================================
data/DSA/list
=====================================
@@ -128,7 +128,7 @@
{CVE-2025-70103}
[trixie] - jpeg-xl 0.11.2-0.1~deb13u2
[11 Jun 2026] DSA-6341-1 ironic - security update
- {CVE-2024-44082 CVE-2026-42510 CVE-2026-42997 CVE-2026-44916 CVE-2026-44917 CVE-2026-44919 CVE-2026-46447 CVE-2026-48681}
+ {CVE-2026-44917 CVE-2026-46447 CVE-2026-48681}
[bookworm] - ironic 1:21.4.4-0+deb12u1
[trixie] - ironic 1:29.0.5-0+deb13u2
[11 Jun 2026] DSA-6340-1 neutron - security update
=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -14,14 +14,6 @@ CVE-2026-25727
[bookworm] - rust-time 0.3.9-1+deb12u1
CVE-2021-37746
[bookworm] - sylpheed 3.8.0~beta1-1+deb12u1
-CVE-2026-42510
- [bookworm] - ironic 1:21.1.0-3+deb12u1
-CVE-2025-44021
- [bookworm] - ironic 1:21.1.0-3+deb12u1
-CVE-2026-42997
- [bookworm] - ironic 1:21.1.0-3+deb12u1
-CVE-2026-44916
- [bookworm] - ironic 1:21.1.0-3+deb12u1
CVE-2025-10148
[bookworm] - curl 7.88.1-10+deb12u15
CVE-2025-14524
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e3902231108475dfcb674c1946ceff8634a54a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8e3902231108475dfcb674c1946ceff8634a54a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260710/9df8ec18/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list