Source: octavia Version: 16.0.0-2 Severity: important Tags: patch security X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at: https://security.openstack.org/ossa/OSSA-2026-035.html Date: August 13, 2026 CVE: CVE-2026-74248 Affects: Octavia: <16.0.2, ==17.0.0, ==18.0.0 Description: Chen YuXiang with the Institute of Computing Technology, Chinese Academy of Sciences, reported a vulnerability in Octavia quality of service (QoS) policy authorization. By associating another project’s QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected. Errata: MITRE assigned CVE-2026-74248 after intial publication. Patches: https://review.opendev.org/1000296 (2025.1/epoxy) https://review.opendev.org/1000295 (2025.2/flamingo) https://review.opendev.org/1000094 (2026.1/gazpacho) https://review.opendev.org/998935 (2026.2/hibiscus (development)) Credits: Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-74248) References: https://launchpad.net/bugs/2161500 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74248 OSSA History: 2026-08-17 - Errata 1 2026-08-13 - Original Version

