-------------------------------------------------------------------------
Debian LTS Advisory DLA-4743-1                [email protected]
https://www.debian.org/lts/security/          Carlos Henrique Lima Melara
August 16, 2026                               https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : ironic
Version        : 1:21.4.4-0+deb12u2
CVE ID         : CVE-2026-43003 CVE-2026-54421
Debian Bug     : 1140012 1140187 1144214

Multiple vulnerabilities were discovered in Ironic, the OpenStack bare metal
hypervisor API for OpenStack.

CVE-2026-54421

    Sensitive properties returned unredacted in POST and PATCH HTTP
    responses.

CVE-2026-43003

    Command injection via chroot execution of tenant-controlled
    binaries.

OSSN-0106

    API ramdisk endpoints require network-level access controls.


For Debian 12 bookworm, these problems have been fixed in version
1:21.4.4-0+deb12u2.

We recommend that you upgrade your ironic packages.

For the detailed security status of ironic please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ironic

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to