Hi Thomas, On Tue, Jul 28, 2026 at 03:06:57PM +0200, Thomas Goirand wrote: > Source: ironic-python-agent > Version: 10.2.0-3 > Severity: important > Tags: patch security > X-Debbugs-Cc: Debian Security Team <[email protected]> > > As per upstream announce: > > > ===================================================================================== > OSSA-2026-028: Credential extraction from Ironic Python Agent via malicious > container > ===================================================================================== > > :Date: July 23, 2026 > :CVE: CVE-2026-54422 > > > Affects > ~~~~~~~ > - Ironic-python-agent: >=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1 > > > Description > ~~~~~~~~~~~ > Yuliang Xiao reported a vulnerability in Ironic Python Agent's bootc > container deployment support. A malicious container can extract the > secrets used to fetch from the OCI registry on deployment. > > Operators can fix this issue by applying the provided patches or completely > disabling the bootc deploy_interface on their Ironic conductors. > > Any Ironic user with the ability to deploy arbitrary containers from the > bootc deploy_interface can exploit this.
Already filled earlier #1142854, so merging both. Regards, Salvatore

