[DSA 6445-1] ironic security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6445-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 17, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : ironic
CVE ID         : CVE-2026-43003 CVE-2026-44918 CVE-2026-54421
                 CCE-2026-54423

Multiple security vulnerabilities were discovered in Ironic,
the OpenStack component to management and provision of baremetal
servers, which could result in bypass of administrative access/API
restrictions, information disclosure or the execution of arbitrary
code via malformed images.

For the stable distribution (trixie), these problems have been fixed in
version 1:29.0.5-0+deb13u3.

We recommend that you upgrade your ironic packages.

For the detailed security status of ironic please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ironic

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqDV/0ACgkQEMKTtsN8
TjYAqhAAk9jfGcVv2cmMX680UgKLRCYdkon2rKr/6JpLxn3t91SSFEd0pfiGyPy/
2dFcUcFhqh1BZsWtWWINTKpIb/+jg66IJj161nkJgE4xcoi70dviYvxJLrNrzSFW
uJAgu6r+TSie8VgKH1Br4+2dQc4Yhm3dM/2k/N34BI63CEkqSikTb+4DvrNbaIUy
ZqTf66Vvh+7MeDUuGFoiMFbcmoy0gLYIqKZovfbppKoEgsC7mFyJFKQF/ambg7LG
wwGSsPVxN1zeHhZQ2o7lrZgAxgVRgZPHV3jgQTCQ36PvrFr+XiZ2uqFf3lRCdn4s
PujTm8aeXW2L+o+Ovt/huvLShROEqj/TFI1tidMPsaxFgf0UXhN2T69ZhzlP6Jqz
cjfSt1lGL75tetJUdJ23GemiGSpmvF7fcUKkyv3gGdNr86slEAA5rp19+C7VcVBm
//WXY3qBR1IkleoycMFFhD17ARy0a10KeObVkviA6hLPLJ4vDqaQwbbDxrnbI9GY
A3CP5F5eH1lt4ciEpbN1TnSvDaNqWF+RV2vRjwSE6FAiJfHicugX62h8bWboXgrs
UF3mhuS6cN+mJo1jMlKBGcgdyM+FyH3jMm0XJGjB44sd9QHD543BoT9UksHPRsv9
/orUaarjvXN71LQyYJHL8xOjDm2PzmDDOPDXDZnJXAfDmnaYm/U=
=r3d3
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.