Source: ironic
Version: 1:29.0.5-0+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-033.html


Date: August 05, 2026
CVE: CVE-2026-71201
Affects: Ironic: >=34.0.0 <35.0.2, >=36.0.0 <38.0.1

Description:

Chen YuXiang of Institute of Computing Technology, Chinese Academy of
Sciences reported an issue in Ironic’s API. When a project reader
requests a list of portgroups filtered by shard, all portgroups in that
shard are returned, not just those in their project.

This is a similar vulnerability to the one originally advisoried in
OSSA-2026-026 – that issue impacted ports; this impacts portgroups.

Patches:
    https://review.opendev.org/999762 (2026.1/gazpacho)
    https://review.opendev.org/999656 (2026.2/hibiscus (development))
    https://review.opendev.org/999765 (Bugfix/34.0)
    https://review.opendev.org/999764 (Bugfix/37.0)
    https://review.opendev.org/999763 (Bugfix/38.0)

Credits
    Chen YuXiang from Institute of Computing Technology, Chinese
    Academy of Sciences

References:
    https://launchpad.net/bugs/2162715
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71201

Notes:
    Ironic bugfix branch patches will be available in git for interested
    operators. We will not perform an additional release from these
    branches.

Reply via email to