|
|
Log in / Subscribe / Register

Ubuntu alert USN-8421-1 (ironic)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8421-1] Ironic vulnerabilities
Date:  Thu, 11 Jun 2026 22:52:44 +0000
Message-ID:  <E1wXoGS-000254-Li@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8421-1 June 11, 2026 ironic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Ironic. Software Description: - ironic: OpenStack service which provides the capability to orchestrate bare metal servers Details: Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not properly validate file paths when handling ISO images. A privileged authenticated remote user could use this issue to perform path traversal via a crafted ISO image and overwrite arbitrary files on the Ironic conductor. (CVE-2026-48681) Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not properly validate kernel command line parameters. A privileged authenticated remote user could use this issue to inject scripts during node boot and possibly execute arbitrary code. (CVE-2026-46447) Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic incorrectly restricted access to custom PXE templates. A privileged authenticated remote user could use this issue to read arbitrary sensitive files on the Ironic conductor. (CVE-2026-44917) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS ironic-api 1:35.0.0-0ubuntu2.1 ironic-common 1:35.0.0-0ubuntu2.1 ironic-conductor 1:35.0.0-0ubuntu2.1 python3-ironic 1:35.0.0-0ubuntu2.1 Ubuntu 25.10 ironic-api 1:32.0.0-0ubuntu1.1 ironic-common 1:32.0.0-0ubuntu1.1 ironic-conductor 1:32.0.0-0ubuntu1.1 python3-ironic 1:32.0.0-0ubuntu1.1 Ubuntu 24.04 LTS ironic-api 1:24.1.1-0ubuntu1.3 ironic-common 1:24.1.1-0ubuntu1.3 ironic-conductor 1:24.1.1-0ubuntu1.3 python3-ironic 1:24.1.1-0ubuntu1.3 Ubuntu 22.04 LTS ironic-api 1:20.1.0-0ubuntu1.3 ironic-common 1:20.1.0-0ubuntu1.3 ironic-conductor 1:20.1.0-0ubuntu1.3 python3-ironic 1:20.1.0-0ubuntu1.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8421-1 CVE-2026-44917, CVE-2026-46447, CVE-2026-48681 Package Information: https://launchpad.net/ubuntu/+source/ironic/1:35.0.0-0ubu... https://launchpad.net/ubuntu/+source/ironic/1:32.0.0-0ubu... https://launchpad.net/ubuntu/+source/ironic/1:24.1.1-0ubu... https://launchpad.net/ubuntu/+source/ironic/1:20.1.0-0ubu...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmorO3oACgkQcpJm3tlz hgH+1Q//fOrs2g/3ICjt/72y51pR480dfOSTMEa5ZtEsq9oK+KZrXBqmo/rg3rEb P9qk97MRhvl2c89iGOg3+VPiq0obLgrwsk/+sY3U+q578ZKn3dm+ydVbn5g3NNWD mWsGpyf3UbE5e2BGUYE7lo4Em25h+LRNDBRIl2c3UW2UtGnNno0fSas6ZFFDA6ni WQO4vk2bJm8AFJQof8+uyXC5rbanTqYxzzLGUbk6UQLO5GReWnnTZPGv/KPsa2+R qJ1sa6GJbUGROWxGNnV5iaHxtjgleN7Yt8KRuNchlczwzmNBj0PJDNvzxY81Tpgw HyfzpPqtAxeIsUiyq5mF9Kv6Rv/0T52q9TNLGW/mngVyeZRnCnpBIDub7CK50ynd wJC0maRhpH2668VIqEptFm5g+bSjlE7Bm6o3M4UhZqhyNeddH0Spdz2fwbV0EbIE UYY07611HydOxqr90E/+8RQxPYAkMDWNOdt2j9YZAJklgOPABNyBQRUmWo/dEc33 DPqNOFSI/jZjNpkblNaq3zjM6Cjp3vWTFsSQuOcaUkGZPSUwYde7Bmu8bvOubiND tw2rRqYTXfw/V2r/5ulpbBYZBPncgZYUEFoJgcFJx5K3Sts7B207y4vbuttLkQ+7 r5tP7L3nOUuFgruRS53VNH2OCE140abw2WvDjQFv9UoGhQll4+M= =4xDC -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds