-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 16 Jun 2026 12:46:11 +0200 Source: ironic Architecture: source Version: 1:29.0.5-0+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: Debian OpenStack <[email protected]> Changed-By: Thomas Goirand <[email protected]> Closes: 1140012 1140187 1141716 1141717 1144214 Changes: ironic (1:29.0.5-0+deb13u3) trixie-security; urgency=medium . * Add follow-up patch for CVE-2026-46447 (erata1): "Fix kernel parameter parsing for quoted values and whitespace". * CVE-2026-54421: Sensitive properties returned unredacted in POST and PATCH HTTP responses. Added upstream patch: "Fix sensitive properties returned on volume targets" (Closes: #1140012). * CVE-2026-43003 / OSSN-2026-0100: Command injection via chroot execution of tenant-controlled binaries. Added upstream patch: "Add an agent flag to disable installing boatloaders" (Closes: #1140187). * CVE-2026-44918: multiple related vulnerabilities in Ironic RBAC. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. Applied upstream patch: "Prevent rehoming resources to nodes with different owner". (Closes: #1141716). * CVE-2026-54423: A malicious user with access to deploy a node directly via Ironic can specify the IPMI `send_raw` deployment step with a malicious payload and send commands to that nodes' BMC. Applied upstream patches: - Add operator-configurable step disallow lists - block vendor.send_raw (Closes: #1141717). * OSSN-0106: API ramdisk endpoints require network-level access controls. Added upstream patch: "Add [api] enable_ramdisk_endpoints config option" (Closes: #1144214). Checksums-Sha1: da04dddc75a899b7899e72128223af1cb4e9b08a 4096 ironic_29.0.5-0+deb13u3.dsc b6b17bf8a174467edda78a62b7136c12b4058129 1892376 ironic_29.0.5.orig.tar.xz 290b0c28884154dbd452f03ee1e0ed2ea41cb980 76328 ironic_29.0.5-0+deb13u3.debian.tar.xz f4c574d4cb4be5f29c5543190ca5efc849b5f746 23072 ironic_29.0.5-0+deb13u3_amd64.buildinfo Checksums-Sha256: 68cf74aa60d9b886b0cd81e61c4f634cbd677f4014f98fb4df03545cf8cace41 4096 ironic_29.0.5-0+deb13u3.dsc 8381a472d7d79dc798a74917bf1cb8eb7795916d952643b64c7f5dc50532e6d9 1892376 ironic_29.0.5.orig.tar.xz ebc098aa465aa552e42144c2b3134dec8a8e491a3af983d95e4dd38a4e93c8f7 76328 ironic_29.0.5-0+deb13u3.debian.tar.xz 0c648c96ed0e3b334ab24658e5cb6a40e010831d15d710219d8c75a24954df46 23072 ironic_29.0.5-0+deb13u3_amd64.buildinfo Files: 857093036c659e8b533dadf7399c72e3 4096 net optional ironic_29.0.5-0+deb13u3.dsc 52695995363316a16620272afa449301 1892376 net optional ironic_29.0.5.orig.tar.xz 2d02b9797312893595b67dd8290d0748 76328 net optional ironic_29.0.5-0+deb13u3.debian.tar.xz 5111e6499f4f44baa8153842e39e614b 23072 net optional ironic_29.0.5-0+deb13u3_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqBn0kACgkQ1BatFaxr Q/7UmxAAh0C5SnyoEzIPU7bvgNOphwMIdi+FWMjZGljM9lVkezrYkIt9vUypnB3m 7+FrFDnZhMvYzqMkSB7vOPtYby1NlOXggrfbgzTQnPb8PtRh7QdpBeze4kgOpdZY 9T1XKdan8TSOfGiqb+3SlszazvyHHSnx8w3ojjeVGhzRvmJZR8+VzyhFZVBHKyvO jRZOkMgj01hnj+rqGqOzYph9eqo30tLqsJNvjb5roDmA1fwfsnnB3OFtG8HgXvrH 0Ox4HB4uG+Lh+LBEwWg93RLrHs9PAS5GRCV2xbddqoMLVddmfZDqmF5ZoX6OBgO1 2S02mfe2jHEVV/UUM9p+k2urr3JaDkUuEjBXyOaonLmysw5WmOghl1C6jNYht/g2 sj3rMZ6wVGV/hOyS0gatO94zDB1cW7Onx+HRx7+z/OBU+X32lDRpBFnlgPyDgRe3 P1PsK/McRDeXOWV7gCkVlm4Ogdm8IsZD7/ytoc+41I7sIOwYoICIpyDpK+XDUHX/ 3m1UveFp0tRl23OPFbT7b6o3VITyx5Nu0uVvtkYS/3AZdujykDcXsIk2RTdfCVQL W7eyv46AY/B8notOINZoFlQP2tZFdYQg2R+m1zqV+aqTOmFbCQXxhGVWjwZkxhMw ol8HOYb9uVdFZdJuOGtqK2kwbtPW80zFlDaVHau2L5o7f7B4PJs= =wPe8 -----END PGP SIGNATURE-----
pgpZvDuyDZlVo.pgp
Description: PGP signature

