Your message dated Thu, 27 Aug 2026 18:34:08 +0000
with message-id <[email protected]>
and subject line Bug#1145816: fixed in keystone 2:29.0.2-2
has caused the Debian Bug report #1145816,
regarding keystone: CVE-2026-80183
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145816: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145816
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: keystone
Version: 2:29.0.1-2
Severity: grave
Tags: security upstream
Forwarded: https://launchpad.net/bugs/2154645
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for keystone.

CVE-2026-80183[0]:
| In OpenStack Keystone before 29.0.3, any authenticated user holding
| role:reader on any project can list every project-scoped role
| assignment under any domain by passing a domain ID as
| scope.project.id with include_subtree to the GET
| /v3/role_assignments endpoint. The domain's project record has
| domain_id=null, causing the policy domain_id check to pass for any
| caller. With include_names, the response discloses the names and
| home-domain IDs of every user, group, project, and role involved.
| The literal "default" domain ID works against any deployment created
| with keystone-manage bootstrap. An attacker can harvest domain IDs
| from the response and repeat the query to map role assignments
| across the entire cloud. This is caused by misuse of "None" inĀ 
| list_role_assignments_for_tree.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-80183
    https://www.cve.org/CVERecord?id=CVE-2026-80183
[1] https://launchpad.net/bugs/2154645

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: keystone
Source-Version: 2:29.0.2-2
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
keystone, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated keystone package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 27 Aug 2026 20:05:41 +0200
Source: keystone
Architecture: source
Version: 2:29.0.2-2
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1145816
Changes:
 keystone (2:29.0.2-2) unstable; urgency=medium
 .
   * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader
     on any project can list every project-scoped role assignment under any
     domain by passing a domain ID as scope.project.id with include_subtree to
     the GET /v3/role_assignments endpoint. The domain's project record has
     domain_id=null, causing the policy domain_id check to pass for any caller.
     With include_names, the response discloses the names and home-domain IDs of
     every user, group, project, and role involved. The literal "default" domain
     ID works against any deployment created with keystone-manage bootstrap. An
     attacker can harvest domain IDs from the response and repeat the query to
     map role assignments across the entire cloud. This is caused by misuse of
     "None" in list_role_assignments_for_tree.
     Applied upstream patch (Closes: #1145816):
     - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch
Checksums-Sha1:
 9a83e651cb6f894ab37b46e4701860c8ca3bb21f 3458 keystone_29.0.2-2.dsc
 c164147be6e03d79e462621eae6708fe782ceaeb 64044 keystone_29.0.2-2.debian.tar.xz
 d0030c4f2531e1d582a570a1f1ef218d080a0fcf 17314 
keystone_29.0.2-2_amd64.buildinfo
Checksums-Sha256:
 1c465331fa1554b51df80dfff3276ee81820dbcd8834509e130285be0a2aaf2e 3458 
keystone_29.0.2-2.dsc
 77d04de4bdc2c3aafe2803f8fdc4952c403f8fbdf5d3f51f249785f67486b487 64044 
keystone_29.0.2-2.debian.tar.xz
 c8fc7c4ebf6f941ea26ee4566e282cebd98057e68d58ca4b3ae7d0a7d7b863fa 17314 
keystone_29.0.2-2_amd64.buildinfo
Files:
 a473c414ef04aec3c076b5cb2e06b85d 3458 net optional keystone_29.0.2-2.dsc
 3f799fcf20aa899a1aa4cd76f04b85ec 64044 net optional 
keystone_29.0.2-2.debian.tar.xz
 2b288ec626eb538472a8e8ffd96c6c90 17314 net optional 
keystone_29.0.2-2_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqQgDIACgkQ1BatFaxr
Q/4H8g/+NWeLwJ8c7uo73v6oXY6e8WJSpiD6545v8foQurI+UlkfqvpAiXOgdbwh
2viYHMiBUgnKi+vHImOEPffVxKuZM+j9MGqZtLkuav7VstOGBOKw48TmdBqbE4JK
MoQ0gguVxod5MJWAxtgN8yWaTihcGVGOUJ7lQhlSgYhuKNlBhEEgFbFx6M/6u2mj
PfKy06SHQLLann38inF+cbQ+uCzolrogYvV3T/dx3UU4q8By5d1rxsiZh6uIZFSw
J7gw7cowY5+FAYp8oZmLT3RGfoi/PN1FrurY8ICvwKaikYpNbvb1ZCW2/F/rb/J0
eD/EoTaPfujP25og3gMKRco419d7vPkVTsQaRVD3sjd5qaN+Z3kCvRiJuG2HyOcL
D7iC1AuWMx5vP7SZXYth1QQaaK75Er02G3gtwuJiyPGe/uGJV1EAR0GDxnrTIvBe
kxWFN2zfLm0oqpzBdj/FSfXhpL4kwvg4UvJqnmFuy7PaGHQlX56stWk0JQpyIoi9
ZVdXQ1cdoFeDzqXhUD+41I2B7+dR/H7yBV4i8qjWzy2kB6hOzXAwuMWC+6sP7HNh
cJnTLv6KAgZ4XpNB6VBaKQmttfnn8HrqGRsxeswr1oHQ8Bx+rAQoebEaR0NdUVhW
AaB1c1uPcwTG/xSeP98K5lXQkENYNf9kirrmOOYquXcyIwOcZ08=
=ry5J
-----END PGP SIGNATURE-----

Attachment: pgpBWcOIt0UHS.pgp
Description: PGP signature


--- End Message ---

Reply via email to