Accepted designate 1:20.0.0-2+deb13u1 (source) into proposed-updates

Debian FTP Masters <[email protected]>
Newsgroups gmane.linux.debian.devel.changes.stable
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 06 Aug 2026 10:25:23 +0200
Source: designate
Architecture: source
Version: 1:20.0.0-2+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144145
Changes:
 designate (1:20.0.0-2+deb13u1) trixie-security; urgency=medium
 .
   * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034:
     - An authenticated tenant can bypass zone ownership checks by scheduling a
       zone to a different pool, creating overlapping zones that hijack or deny
       service to another tenant's DNS records. Any user with the default
       create_zone policy can exploit this when the AttributeFilter scheduler is
       enabled. Only deployments using the AttributeFilter scheduler with
       multiple pools are affected.
     - The mDNS handler performs pool-blind record lookups that fail when
       colliding zones exist across pools, causing deterministic DNS query
       failures. The NOTIFY handler path is reachable via unauthenticated UDP.
     Applied upstream patches:
     - Require TSIG keys for zones in non-default pools
     - Fix mDNS record query pool scoping for split-horizon DNS
     - Fix cross-tenant/cross-pool zone ownership bypass
     (Closes: #1144145).
Checksums-Sha1:
 9600252d6b8c34dd885f28de0c52dc76530a6ed5 4337 designate_20.0.0-2+deb13u1.dsc
 2b6fd38f47f475cd9859ad72aea0c69641c58681 738480 designate_20.0.0.orig.tar.xz
 412dac3864a842a1977403c994ff9230f876d838 26400 designate_20.0.0-2+deb13u1.debian.tar.xz
 9867748b282616dd4582d8ce3315318e14f88ace 22467 designate_20.0.0-2+deb13u1_amd64.buildinfo
Checksums-Sha256:
 ad52c9d0f53502990025b3b939bbe46cae854e8678902ab75e599a3a3fc44100 4337 designate_20.0.0-2+deb13u1.dsc
 c63c1c95728b1cc258b00f8885e5a85ef170f6fd5a2e71c7be6735ae556c385a 738480 designate_20.0.0.orig.tar.xz
 9957e940feb74976c78bf9c49bcb07aa5944d978051d03a1cf17c1c13c79e250 26400 designate_20.0.0-2+deb13u1.debian.tar.xz
 1f447c470f23006cddd32e2021f1cef69c04f27a900e2918ceba322bae611628 22467 designate_20.0.0-2+deb13u1_amd64.buildinfo
Files:
 f39c8f39533eb81224e23f65d18ed6b2 4337 net optional designate_20.0.0-2+deb13u1.dsc
 b694063b70a4a1f770fd56fbd3a3ab34 738480 net optional designate_20.0.0.orig.tar.xz
 bdfda1e13304bc974868fac699fdd9d9 26400 net optional designate_20.0.0-2+deb13u1.debian.tar.xz
 c0934ae5185cae297414e6443bb8142e 22467 net optional designate_20.0.0-2+deb13u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqEgugACgkQ1BatFaxr
Q/6o/A/+JVxSEDOOujYw4Uw1hOKUW1cJ1+zEDMZyDC0mzEv8h1o3u/wMC/RbV4Qx
lyP7wMTlRSNcgUMayh4LeTfYZxW/GkgLIIOXv3nQLe7A9h51G+OR3rbwW8hje+60
vsRoxbj5fGIrN3PvlIM734sQ9AibOQeohhJ50sFOv1wiTOCfTjzt/IJ6npssuib7
bf6XdbZruhG/LuJoV4oUVF1TTc4hiVcTrGS1ld7g4ANw0A1THbrAkC8nZprWTEx/
4zl8EE+ruirlBNFl2rkA30qulKBLd7HHZKiwYCTeT7dpsrPYN10QoIzO3k245uW+
JH9bsNT/4cx5ZXZQKv8znIytWZDF+EVqgas9x8tA/oP6IfBBEhSDKCIUYBbECcdb
pYwx5ZBjyzKp4fHSfLjmpaNFdFcaVY7djZR/jLlqrY57gh7omyZf+Ntl8nMbGWoG
SAV86DZ58GfxMHw4CYsj8AHlgr+AkvmeKpL9h5egd2uqTHtDnnw35iMkobDsFxst
m/JwG0kY1ha8iFeGbKMSgwFo67rdO7dzxW8uUzKLcKKD++3M0Os3Dq01CJw4p6d4
GxFLphhXKK77WagVmGjINfKldX1LTv5wFT+1YVa/snfRbVp96MJqYS7ZiZ4HLjRw
qMyU5AdY042Qt0DCZQtrFTuK4vgtlZmHCnYDiKQWkiH0+CCbggk=
=hlv3
-----END PGP SIGNATURE-----
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaozGZQAKCRCb9qggYcy5
IQhJAQDPRtxlNfRsC5zV8TWkrh+3cl48zbq9fDwAYiuvQ4cS8AD/eB2sIaUCixfF
bq2n1O8rt1EJBfdJ87RDCaTbMq1HbAU=
=7zfu
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.