Your message dated Mon, 24 Aug 2026 22:32:05 +0000
with message-id <[email protected]>
and subject line Bug#1144145: fixed in designate 1:20.0.0-2+deb13u1
has caused the Debian Bug report #1144145,
regarding CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: Cross-tenant DNS zone
overlap and mDNS DoS via pool scheduling
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144145: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144145
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: designate
Version: 1:20.0.0-2
Severity: serious
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-034.html
Date:
August 11, 2026
CVE:
CVE-2026-71193, CVE-2026-71194
Affects:
Designate: >=1.0.0 <20.0.2, ==21.0.0, ==22.0.0
Description:
Tore Anderson of Redpill Linpro AS reported that OpenStack Designate does not
enforce cross-pool zone ownership checks when scheduling a zone to a
non-default pool via the attribute filter. A tenant can create a sub-zone,
super-zone, or duplicate of another tenant’s zone by targeting a different
pool, enabling DNS hijack or denial of service. Independently, Omer Schwartz
of Red Hat identified that the mDNS handler performs pool-blind record
lookups, causing a deterministic denial of service when colliding zones exist
across pools. All deployments using multiple Designate pools are affected.
Patches:
https://review.opendev.org/1000475 (2025.1/epoxy)
https://review.opendev.org/1000474 (2025.2/flamingo)
https://review.opendev.org/1000473 (2026.1/gazpacho)
https://review.opendev.org/1000471 (2026.2/hibiscus (development))
Credits:
Tore Anderson from Redpill Linpro AS
Omer Schwartz from Red Hat
References:
https://launchpad.net/bugs/2160533
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71194
Notes:
The stable branch patches depend on two prerequisite backports (mDNS
split-horizon pool scoping, Change 998005/998006 and their stable equivalents)
that were merged before disclosure. Operators applying the fix to releases
older than the next point release should ensure those prerequisite commits are
present.
Operators should audit existing zones for cross-tenant collisions that may
have been created before the fix. A detection tool will be proposed as a
separate public patch.
--- End Message ---
--- Begin Message ---
Source: designate
Source-Version: 1:20.0.0-2+deb13u1
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
designate, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated designate package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 06 Aug 2026 10:25:23 +0200
Source: designate
Architecture: source
Version: 1:20.0.0-2+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144145
Changes:
designate (1:20.0.0-2+deb13u1) trixie-security; urgency=medium
.
* CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034:
- An authenticated tenant can bypass zone ownership checks by scheduling a
zone to a different pool, creating overlapping zones that hijack or deny
service to another tenant's DNS records. Any user with the default
create_zone policy can exploit this when the AttributeFilter scheduler is
enabled. Only deployments using the AttributeFilter scheduler with
multiple pools are affected.
- The mDNS handler performs pool-blind record lookups that fail when
colliding zones exist across pools, causing deterministic DNS query
failures. The NOTIFY handler path is reachable via unauthenticated UDP.
Applied upstream patches:
- Require TSIG keys for zones in non-default pools
- Fix mDNS record query pool scoping for split-horizon DNS
- Fix cross-tenant/cross-pool zone ownership bypass
(Closes: #1144145).
Checksums-Sha1:
9600252d6b8c34dd885f28de0c52dc76530a6ed5 4337 designate_20.0.0-2+deb13u1.dsc
2b6fd38f47f475cd9859ad72aea0c69641c58681 738480 designate_20.0.0.orig.tar.xz
412dac3864a842a1977403c994ff9230f876d838 26400
designate_20.0.0-2+deb13u1.debian.tar.xz
9867748b282616dd4582d8ce3315318e14f88ace 22467
designate_20.0.0-2+deb13u1_amd64.buildinfo
Checksums-Sha256:
ad52c9d0f53502990025b3b939bbe46cae854e8678902ab75e599a3a3fc44100 4337
designate_20.0.0-2+deb13u1.dsc
c63c1c95728b1cc258b00f8885e5a85ef170f6fd5a2e71c7be6735ae556c385a 738480
designate_20.0.0.orig.tar.xz
9957e940feb74976c78bf9c49bcb07aa5944d978051d03a1cf17c1c13c79e250 26400
designate_20.0.0-2+deb13u1.debian.tar.xz
1f447c470f23006cddd32e2021f1cef69c04f27a900e2918ceba322bae611628 22467
designate_20.0.0-2+deb13u1_amd64.buildinfo
Files:
f39c8f39533eb81224e23f65d18ed6b2 4337 net optional
designate_20.0.0-2+deb13u1.dsc
b694063b70a4a1f770fd56fbd3a3ab34 738480 net optional
designate_20.0.0.orig.tar.xz
bdfda1e13304bc974868fac699fdd9d9 26400 net optional
designate_20.0.0-2+deb13u1.debian.tar.xz
c0934ae5185cae297414e6443bb8142e 22467 net optional
designate_20.0.0-2+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqEgugACgkQ1BatFaxr
Q/6o/A/+JVxSEDOOujYw4Uw1hOKUW1cJ1+zEDMZyDC0mzEv8h1o3u/wMC/RbV4Qx
lyP7wMTlRSNcgUMayh4LeTfYZxW/GkgLIIOXv3nQLe7A9h51G+OR3rbwW8hje+60
vsRoxbj5fGIrN3PvlIM734sQ9AibOQeohhJ50sFOv1wiTOCfTjzt/IJ6npssuib7
bf6XdbZruhG/LuJoV4oUVF1TTc4hiVcTrGS1ld7g4ANw0A1THbrAkC8nZprWTEx/
4zl8EE+ruirlBNFl2rkA30qulKBLd7HHZKiwYCTeT7dpsrPYN10QoIzO3k245uW+
JH9bsNT/4cx5ZXZQKv8znIytWZDF+EVqgas9x8tA/oP6IfBBEhSDKCIUYBbECcdb
pYwx5ZBjyzKp4fHSfLjmpaNFdFcaVY7djZR/jLlqrY57gh7omyZf+Ntl8nMbGWoG
SAV86DZ58GfxMHw4CYsj8AHlgr+AkvmeKpL9h5egd2uqTHtDnnw35iMkobDsFxst
m/JwG0kY1ha8iFeGbKMSgwFo67rdO7dzxW8uUzKLcKKD++3M0Os3Dq01CJw4p6d4
GxFLphhXKK77WagVmGjINfKldX1LTv5wFT+1YVa/snfRbVp96MJqYS7ZiZ4HLjRw
qMyU5AdY042Qt0DCZQtrFTuK4vgtlZmHCnYDiKQWkiH0+CCbggk=
=hlv3
-----END PGP SIGNATURE-----
pgpQGfMu6Vf8w.pgp
Description: PGP signature
--- End Message ---