Hi Thomas,

On Tue, Jul 28, 2026 at 03:06:57PM +0200, Thomas Goirand wrote:
> Source: ironic-python-agent
> Version: 10.2.0-3
> Severity: important
> Tags: patch security
> X-Debbugs-Cc: Debian Security Team <[email protected]>
> 
> As per upstream announce:
> 
> 
> =====================================================================================
> OSSA-2026-028: Credential extraction from Ironic Python Agent via malicious 
> container
> =====================================================================================
> 
> :Date: July 23, 2026
> :CVE: CVE-2026-54422
> 
> 
> Affects
> ~~~~~~~
> - Ironic-python-agent: >=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1
> 
> 
> Description
> ~~~~~~~~~~~
> Yuliang Xiao reported a vulnerability in Ironic Python Agent's bootc
> container deployment support. A malicious container can extract the
> secrets used to fetch from the OCI registry on deployment.
> 
> Operators can fix this issue by applying the provided patches or completely
> disabling the bootc deploy_interface on their Ironic conductors.
> 
> Any Ironic user with the ability to deploy arbitrary containers from the
> bootc deploy_interface can exploit this.

Already filled earlier #1142854, so merging both.

Regards,
Salvatore

Reply via email to