------------------------------------------------------------------------- Debian LTS Advisory DLA-4743-1 [email protected] https://www.debian.org/lts/security/ Carlos Henrique Lima Melara August 16, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : ironic
Version : 1:21.4.4-0+deb12u2
CVE ID : CVE-2026-43003 CVE-2026-54421
Debian Bug : 1140012 1140187 1144214
Multiple vulnerabilities were discovered in Ironic, the OpenStack bare metal
hypervisor API for OpenStack.
CVE-2026-54421
Sensitive properties returned unredacted in POST and PATCH HTTP
responses.
CVE-2026-43003
Command injection via chroot execution of tenant-controlled
binaries.
OSSN-0106
API ramdisk endpoints require network-level access controls.
For Debian 12 bookworm, these problems have been fixed in version
1:21.4.4-0+deb12u2.
We recommend that you upgrade your ironic packages.
For the detailed security status of ironic please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ironic
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
