Your message dated Wed, 15 Jul 2026 17:33:42 +0000
with message-id <[email protected]>
and subject line Bug#1142113: fixed in nova 2:33.0.1-5
has caused the Debian Bug report #1142113,
regarding OSSN-0101: Nova console WebSocket proxy Origin allow-list poisoning
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142113: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142113
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: nova
Version: 2:31.0.0-6+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce at:
https://wiki.openstack.org/wiki/OSSN/OSSN-0101

Summary

The Nova console WebSocket proxy mutates a shared, process-global oslo.config
allowed_origins list on every incoming request by appending the
client-controlled Host header value. Because oslo.config returns a cached list
object, these appends persist for the lifetime of the proxy process. This
permanently weakens the cross-origin protection on the console proxy and
causes unbounded memory growth.

Affected Services / Software
    nova >=12.0.0 <31.3.2, >=32.0.0 <32.2.2, >=33.0.0 <33.0.3

Discussion
On each request, the proxy appends the Host header to
CONF.console.allowed_origins to allow the proxy's own hostname. This mutates
the shared oslo.config cached list rather than operating on a copy, so any
Host value ever seen is retained permanently for the life of the process.

An unauthenticated attacker can inject arbitrary hostnames into the allow-list
by sending requests with crafted Host headers, defeating the Origin check for
all subsequent requests. The unbounded list growth also enables a slow memory
exhaustion DoS.

Recommended Actions
Apply the provided Nova patches. The fix copies the config list before
appending, so mutations do not persist across requests.

Patches
The following reviews contain the fix for this issue:

    2026.2/hibiscus (development): 
https://review.opendev.org/c/openstack/nova/+/995870
    2026.1/gazpacho: https://review.opendev.org/c/openstack/nova/+/995956
    2025.2/flamingo: https://review.opendev.org/c/openstack/nova/+/995957
    2025.1/epoxy: https://review.opendev.org/c/openstack/nova/+/995958

Credits
Sergey r0binak Kanibor, Luntry
Contacts / References

    Authors: Goutham Pacha Ravi, Red Hat

    This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0101
    Original Launchpad bug: https://bugs.launchpad.net/nova/+bug/2158919
    Mailing List : [security-sig] tag on [email protected]
    OpenStack Security : https://security.openstack.org/
    CVE: none

--- End Message ---
--- Begin Message ---
Source: nova
Source-Version: 2:33.0.1-5
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
nova, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated nova package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 15 Jul 2026 14:38:22 +0200
Source: nova
Architecture: source
Version: 2:33.0.1-5
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1142113
Changes:
 nova (2:33.0.1-5) unstable; urgency=high
 .
   * OSSN-0101: Nova console WebSocket proxy Origin allow-list poisoning.
     Applied upstream patch: "Fix mutating global config in websocket proxy"
     (Closes: #1142113).
Checksums-Sha1:
 356230b61671fa5e2c2f4924c08ad5c9f28bf449 4706 nova_33.0.1-5.dsc
 24299cf3e9bb2dddba64bf7eae324ec188deacec 72672 nova_33.0.1-5.debian.tar.xz
 c8cdc35b669131c0e996b1a58c7a62536378bc29 25757 nova_33.0.1-5_amd64.buildinfo
Checksums-Sha256:
 5398cf7ece3524c75d1d4954759acd83898254ff773685e44385a158a2ecae76 4706 
nova_33.0.1-5.dsc
 7e6722fc24d79cacb30a39fff8ead5b8e145cce05a4e3911790ef8e99f49a836 72672 
nova_33.0.1-5.debian.tar.xz
 c0bbd339a60aec7f19b6321ec95665c5061171570dd10f0b3bfee11f61f7bf2b 25757 
nova_33.0.1-5_amd64.buildinfo
Files:
 5e3cf9de8ed2a96ed032a07556bd415b 4706 net optional nova_33.0.1-5.dsc
 4e5ff29e97694d8f816be8bdcd09930d 72672 net optional nova_33.0.1-5.debian.tar.xz
 ef68e2f80d3bf4e1341b7c440abc5d4e 25757 net optional 
nova_33.0.1-5_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmpXv7cACgkQ1BatFaxr
Q/7axRAAgWY9NrYy1mJliVhF6mNlK0J5CDgz2w2UWdJF+KYotkGOiDrcvsWBVXWQ
Eb3SL5ORdZ7pypCXETjjVH7lee70S6upJRebx+5OVFxBLoO3YcjyQJmKI3s1UfmK
4LddGAa9iguoC0HSX3eU1rBT//XKVNL5sD3LEzDeplV1bC7Et2LtKvtJ8n2TL2Tk
2apuqF+9vKBzr8sCUsj6K88rLXvqjhq6nhDVCZT67Mx0ljJPEl7lnGABGVfKkyYX
YTsQv11lzpCmRgnmsbiwtRxj2jz8pEqAtZDmme3FumaJaQYTU2vqFZKI6oG3uAec
pucQXBCGb4POmi3xuit2UBVLDdnL55+fkB7d1Qngomlu/qKNl9wUu2Zpg6p6h8gg
sOntAcxMOjtDDiew6CD+gKCviFGKZXGnvjGHJcdwf7h4TI1FTCFkM+9jcanAMFwk
7EAZQvo9VRm0s/YNOcALA/nuvW/kAT/slPCJuECIn6KbcP7qMoy7UK2sGq5W8And
heiXYfcHpMi/VivjixVnrmDHiIMNJZnpBL3sLEol+qPaXjHK3InQbf2MOQXMP7Ic
zwF6TpG/cEHja3+DUoliGPfN5nP3Q404eQaOncAtOaO7CxqJBddiqJHiWt14PpTp
O487Y6I6vegtjgzgmO2nWJhmTReKRvIx7VoDJEzlnuKh+VQ400o=
=+ElW
-----END PGP SIGNATURE-----

Attachment: pgpz5HccMhChg.pgp
Description: PGP signature


--- End Message ---

Reply via email to