|
|
Log in / Subscribe / Register

Ubuntu alert USN-7926-1 (keystone)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7926-1] OpenStack Keystone vulnerabilities
Date:  Thu, 11 Dec 2025 17:46:48 +0000
Message-ID:  <E1vTkka-0005lr-I7@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7926-1 December 11, 2025 keystone vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in OpenStack Keystone. Software Description: - keystone: OpenStack identity service Details: Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access and escalate privileges. (CVE-2025-65073) It was discovered that OpenStack Keystone only validated the first 72 bytes of an application secret. An attacker could possibly use this issue to bypass password complexity. (CVE-2021-3563) It was discovered that OpenStack Keystone had a time lag before a token should be revoked by the security policy. A remote administrator could use this issue to maintain access for longer than expected. (CVE-2022-2447) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS keystone 2:21.0.1-0ubuntu2.1 python3-keystone 2:21.0.1-0ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7926-1 CVE-2021-3563, CVE-2022-2447, CVE-2025-65073 Package Information: https://launchpad.net/ubuntu/+source/keystone/2:21.0.1-0u...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmk7AzwACgkQcpJm3tlz hgHj9g/6AwlKFQnCK/iq0M0C7cETwwTqq7GQdR3SmW6akQO0vGHUscV0xImwhLW+ RZ/qsFK6HcMqI2Fci2fzwB48zxcVZuamYTkhLdQiMup0g1tTNRgS6X0+S+h8R9q0 DDoTPtoSU84BqN4Qb1xhYKP24O8thKVINMZrb2l4xNJM/xpGIT9nIOB/f1J4yGoQ elxInqOuOgUqh28Gwp2Fq5tAYOjBKlQIVoP7Fk67MnwpE+HD+/pehwfDHpqvyAbd +Rfi/CSaDGWhXG0c4DXp9CW59Z88d7KytLPo5Oqg4IMseyQ5v2x1NPhyNGfwu132 HtO06rwmrZnxudJHIZHMnZby18bYRWfkI+BumkLf/PDqDGHeyqvZR1itgXpDCZLc 5pZElK5vtkMn6Z91ghLiZS37oEjNY7XY7TLVq+4CsN/rTW6nh2J+fguPG+ACoj/u vrD2dLjzUKQbI5UtSeqroONObe/JK8E+7R0D6A8oCvMtLqzJBMEG6bhXSpyc8PAy OdyVq42Jz+j1gbOx0eVJEIaCacteqqB7ZFBTvX9fR1pbyZ2r5ZbKYjJerDm1x3t7 42NPonTu3ljp/2xTzHqz6kcLBLX/iM9yzC/1cjObZF2w2pZqs1bYMjJpESgOXxxS owoqin6M76JNkCM34m+TFyfhuDrYduygDViL9Kd3NhqHufQ/rY8= =nLZc -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds