Source: octavia
Version: 16.0.0-2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>

As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-035.html


Date:
    August 13, 2026

CVE:
    CVE-2026-74248

Affects:
    Octavia: <16.0.2, ==17.0.0, ==18.0.0

Description:
Chen YuXiang with the Institute of Computing Technology, Chinese Academy of
Sciences, reported a vulnerability in Octavia quality of service (QoS) policy
authorization. By associating another project’s QoS policy with an amphora, an
authenticated user may prevent deletion of that policy. All Octavia deployments
are affected.

Errata:
MITRE assigned CVE-2026-74248 after intial publication.

Patches:
    https://review.opendev.org/1000296 (2025.1/epoxy)
    https://review.opendev.org/1000295 (2025.2/flamingo)
    https://review.opendev.org/1000094 (2026.1/gazpacho)
    https://review.opendev.org/998935 (2026.2/hibiscus (development))

Credits:
    Chen YuXiang from Institute of Computing Technology, Chinese Academy of
Sciences (CVE-2026-74248)

References:
    https://launchpad.net/bugs/2161500
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74248

OSSA History:
    2026-08-17 - Errata 1
    2026-08-13 - Original Version

Reply via email to