Hi,I've just uploaded Ironic 1:21.4.4-0+deb12u2 to bookworm-security. Below is what I'd suggest as DLA. Can someone review it, and publish it for me please?
Note I also uploaded an update to Trixie-security today as well. Cheers, Thomas Goirand (zigo) Package : ironic Version : 1:21.4.4-0+deb12u2 CVE ID : CVE-2026-46447 CVE-2026-54421 CVE-2026-43003 Debian Bug : 1140012 1140187 1144214Multiple vulnerabilities were discovered in Ironic, the OpenStack bare metal hypervisor API for OpenStack.
CVE-2026-54421
Sensitive properties returned unredacted in POST and PATCH HTTP
responses.
CVE-2026-43003
Command injection via chroot execution of tenant-controlled
binaries.
OSSN-0106
API ramdisk endpoints require network-level access controls.
For Debian 12 bookworm, this problem has been fixed in version
1:21.4.4-0+deb12u2.
We recommend that you upgrade your ironic packages.
For the detailed security status of ironic please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ironic
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
OpenPGP_signature.asc
Description: OpenPGP digital signature
