Hi,

I've just uploaded Ironic 1:21.4.4-0+deb12u2 to bookworm-security. Below is what I'd suggest as DLA. Can someone review it, and publish it for me please?

Note I also uploaded an update to Trixie-security today as well.

Cheers,

Thomas Goirand (zigo)

Package        : ironic
Version        : 1:21.4.4-0+deb12u2
CVE ID         : CVE-2026-46447 CVE-2026-54421 CVE-2026-43003
Debian Bug     : 1140012 1140187 1144214

Multiple vulnerabilities were discovered in Ironic, the OpenStack bare metal hypervisor API for OpenStack.

CVE-2026-54421

    Sensitive properties returned unredacted in POST and PATCH HTTP
    responses.

CVE-2026-43003

    Command injection via chroot execution of tenant-controlled
    binaries.

OSSN-0106

    API ramdisk endpoints require network-level access controls.

For Debian 12 bookworm, this problem has been fixed in version
1:21.4.4-0+deb12u2.

We recommend that you upgrade your ironic packages.

For the detailed security status of ironic please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ironic

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to