Bug#1144145: marked as pending in designate
Thomas Goirand <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Control: tag -1 pending
Hello,
Bug #1144145 in designate reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:
https://salsa.debian.org/openstack-team/services/designate/-/commit/3981821ff38b01dbe4d1a24d0cd36ee54ffbc404
------------------------------------------------------------------------
* CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034:
- An authenticated tenant can bypass zone ownership checks by scheduling a
zone to a different pool, creating overlapping zones that hijack or deny
service to another tenant's DNS records. Any user with the default
create_zone policy can exploit this when the AttributeFilter scheduler is
enabled. Only deployments using the AttributeFilter scheduler with
multiple pools are affected.
- The mDNS handler performs pool-blind record lookups that fail when
colliding zones exist across pools, causing deterministic DNS query
failures. The NOTIFY handler path is reachable via unauthenticated UDP.
Applied upstream patches:
- Require TSIG keys for zones in non-default pools
- Fix mDNS record query pool scoping for split-horizon DNS
- Fix cross-tenant/cross-pool zone ownership bypass
(Closes: #1144145).
------------------------------------------------------------------------
(this message was generated automatically)