Your message dated Thu, 03 Sep 2026 20:42:45 +0000
with message-id <[email protected]>
and subject line Bug#1146594: fixed in glance 2:32.0.0-4
has caused the Debian Bug report #1146594,
regarding CVE-2026-71196, CVE-2026-71197, CVE-2026-71198, OSSA-2026-038: 
Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIs
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1146594: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146594
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: glance
Severity: serious
Tags: patch

As per upstream announce here:
https://security.openstack.org/ossa/OSSA-2026-038.html


Date:
    September 03, 2026
CVE:
    CVE-2026-71196, CVE-2026-71197, CVE-2026-71198

Affects
    Glance: >=16.0.0 <30.2.1, >=31.0.0 <31.1.1, >=32.0.0 <32.0.1

Description:
Sergey Kanibor (Luntry), Sami Yessou (switch.ch), and Abhishek Kekane (Red Hat)
reported three related SSRF vulnerabilities in OpenStack Glance.

The web-download import method ships with insecure default filtering that
permits authenticated users to fetch arbitrary internal URLs, including cloud
metadata endpoints. The URI validator does not perform DNS resolution before
applying host filters, enabling bypass via attacker-controlled domains and
DNS rebinding attacks. The HTTP image location API lacks host filtering
entirely when the HTTP store is enabled, and fetched content is stored as
image data accessible for download, converting blind SSRF into full-read
exfiltration.

All Glance deployments using the web-download import method or HTTP image
location APIs are affected.

Patches:
    https://review.opendev.org/1003822 (2025.1/epoxy)
    https://review.opendev.org/1003823 (2025.1/epoxy)
    https://review.opendev.org/1003824 (2025.1/epoxy)
    https://review.opendev.org/1003825 (2025.1/epoxy)

    https://review.opendev.org/1003816 (2025.2/flamingo)
    https://review.opendev.org/1003817 (2025.2/flamingo)
    https://review.opendev.org/1003818 (2025.2/flamingo)
    https://review.opendev.org/1003819 (2025.2/flamingo)

    https://review.opendev.org/1003812 (2026.1/gazpacho)
    https://review.opendev.org/1003813 (2026.1/gazpacho)
    https://review.opendev.org/1003814 (2026.1/gazpacho)
    https://review.opendev.org/1003815 (2026.1/gazpacho)

    https://review.opendev.org/1003805 (2026.2/hibiscus (development))
    https://review.opendev.org/1003806 (2026.2/hibiscus (development))
    https://review.opendev.org/1003807 (2026.2/hibiscus (development))
    https://review.opendev.org/1003808 (2026.2/hibiscus (development))

Credits

    Sergey Kanibor from Luntry (CVE-2026-71196, CVE-2026-71197)
    Sami Yessou from switch.ch (CVE-2026-71196)
    Abhishek Kekane from Red Hat (CVE-2026-71198)

References
    https://launchpad.net/bugs/2158998
    https://launchpad.net/bugs/2158999
    https://launchpad.net/bugs/2161330
    https://launchpad.net/bugs/2160020
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71196
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71197
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71198

Notes
    All four commits in each patch set are interdependent and must be applied
together, in the order listed above, as each builds on the previous. The DoS
issue (LP#2160020) is addressed as part of this coordinated fix.

    A related Tempest test compatibility fix was proposed at
https://review.opendev.org/1003560

--- End Message ---
--- Begin Message ---
Source: glance
Source-Version: 2:32.0.0-4
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
glance, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated glance package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 28 Aug 2026 10:50:37 +0200
Source: glance
Architecture: source
Version: 2:32.0.0-4
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1146594
Changes:
 glance (2:32.0.0-4) unstable; urgency=high
 .
   * CVE-2026-71196, CVE-2026-71197, CVE-2026-71198: Multiple SSRF
     vulnerabilities. Applied upstream patches:
     - CVE-2026-71196-71197-71198_1_Properly_limit_web-download_image_f....patch
     - CVE-2026-71196-71197-71198_2_Block_restricted_addresses_in_web-d....patch
     - CVE-2026-71196-71197-71198_3_Pin_import_downloads_to_validated_d....patch
     - CVE-2026-71196-71197-71198_4_Block_restricted_hosts_when_adding_....patch
     (Closes: #1146594)
Checksums-Sha1:
 b3184118dac8b7c3b2f7b026f468af8c6d25b04b 3707 glance_32.0.0-4.dsc
 520c622c2668c8afdceb445e682b61649aa076f1 39292 glance_32.0.0-4.debian.tar.xz
 9a9ceeead2fbe5e5ab441cff5e0b5bb4ef1268d2 18727 glance_32.0.0-4_amd64.buildinfo
Checksums-Sha256:
 0172026b91a6927487deb323ff94ea0f631a7a9c86b7255a381beb3b52e47f13 3707 
glance_32.0.0-4.dsc
 865d7eebb128b8f0697a618f2c7ffa5d24636fc16448d57b5867494dcdee52a2 39292 
glance_32.0.0-4.debian.tar.xz
 7c30f0786068aa2a791d9bbed0bbfbc75b234332578433ee46b9ff31c678cc5f 18727 
glance_32.0.0-4_amd64.buildinfo
Files:
 6f0580204d0dd790c57d636f5f498067 3707 net optional glance_32.0.0-4.dsc
 8d9be09dc2bbd590d1597103a6dcc419 39292 net optional 
glance_32.0.0-4.debian.tar.xz
 6d225b0fdbb41267de4ac5c690b3bf60 18727 net optional 
glance_32.0.0-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqZ0AEACgkQ1BatFaxr
Q/4HVA//TKQV3lQuJSb9lq5Wf+ODT9Qyv7+b90v007gfHzHQGBrep9G+yMRcEZEG
8Qud5c7Kxt2vvOiqPiX+so4btAEEj5thyAO9PD672uCnrBB8tZZaRXaZ8SIv6r0+
T6x/hScvCUPmvoMm0T9YnGryFyBcDcWXGQg47tkKdMw+DapGZtks20CMeo3IUBbw
heLdW3o1WEceMWvsK7fsRDMdGXvQmN2oq14gc1Q/DuPWUq02qSB+kD+q1nQQ4riF
4CSAzd36ubCdj9ttefb/tXd9xLAsfBtO42t7x69Bnq/aHUM46nRZiwQVOCF9jrT7
kR/NIE6TbnzF575d5nDmk0qfJihRlAikbDwEK+TPgKFjrWTogFCHEV4ntH3JRfIG
fv2VYf+tPNdmN4vIorZwt0vXmzMeutqy/hlTS6SUje1/n2tQszn7UqnLFFt6YyAR
IEmJeloSjJA/g+4uC7LHDaYk/KRIUNJNd3BQbng4QlYvQBKfqZH505e+ZzucZE+p
TqrKoJHH0HjlKYLLhpcwhOITB66MfzMhVOTWFHQRL3b6e3cX/qyA+YpMlxD7cOh1
xPSTsKRS2vzTDBvtmlGCbNuL9Hyo4D6X63mLUXMUXBdpIQecMdMhKsv/xJJH3MZU
8i3VJoZzeTo4tQFzbEn8z9rFB8LYVd5jjcNdfjNHPTLlDfffdXk=
=5QT2
-----END PGP SIGNATURE-----

Attachment: pgpcr6N781fAj.pgp
Description: PGP signature


--- End Message ---

Reply via email to