Ubuntu alert USN-8422-1 (mistral)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8422-1] Mistral vulnerability | |
| Date: | Thu, 11 Jun 2026 15:29:24 +0000 | |
| Message-ID: | <E1wXhLQ-0000Fl-D3@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8422-1 June 11, 2026 mistral vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Mistral could be made to expose sensitive information or run code. Software Description: - mistral: OpenStack Workflow Service Details: Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that Mistral did not properly enforce access policies on some API endpoints. An attacker could possibly execute arbitrary code on a Mistral worker and possibly extract sensitive data including service credentials from it. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS mistral-api 22.0.0-0ubuntu1.1 mistral-common 22.0.0-0ubuntu1.1 mistral-engine 22.0.0-0ubuntu1.1 mistral-event-engine 22.0.0-0ubuntu1.1 mistral-executor 22.0.0-0ubuntu1.1 python3-mistral 22.0.0-0ubuntu1.1 Ubuntu 25.10 mistral-api 21.0.0-0ubuntu1.1 mistral-common 21.0.0-0ubuntu1.1 mistral-engine 21.0.0-0ubuntu1.1 mistral-event-engine 21.0.0-0ubuntu1.1 mistral-executor 21.0.0-0ubuntu1.1 python3-mistral 21.0.0-0ubuntu1.1 Ubuntu 24.04 LTS mistral-api 18.0.1-0ubuntu1.1 mistral-common 18.0.1-0ubuntu1.1 mistral-engine 18.0.1-0ubuntu1.1 mistral-event-engine 18.0.1-0ubuntu1.1 mistral-executor 18.0.1-0ubuntu1.1 python3-mistral 18.0.1-0ubuntu1.1 Ubuntu 22.04 LTS mistral-api 14.0.0-0ubuntu1.1 mistral-common 14.0.0-0ubuntu1.1 mistral-engine 14.0.0-0ubuntu1.1 mistral-event-engine 14.0.0-0ubuntu1.1 mistral-executor 14.0.0-0ubuntu1.1 python3-mistral 14.0.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8422-1 CVE-2026-41283 Package Information: https://launchpad.net/ubuntu/+source/mistral/22.0.0-0ubun... https://launchpad.net/ubuntu/+source/mistral/21.0.0-0ubun... https://launchpad.net/ubuntu/+source/mistral/18.0.1-0ubun... https://launchpad.net/ubuntu/+source/mistral/14.0.0-0ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoq0n0ACgkQcpJm3tlz hgFNIw/+Irq5rKcvaDaslz6GF2IZKBtH5jAALKWAo6JMnQxXOu1JJ2J37zmtxPsX Ox9Asbadv+PMIvznyssUAvTVX3+O2EtoTqs29Lm7yCjHyt/BkfsbxSyX5x5NDN+w r9wflzOV2KJG92fm47vN4N1os4R7A1jyuYz2SRQmNN3R0v4dZlGyl9uqHN2ccaw8 gSq+rAttdHM1kNrYVC2T98/3dIKMxCrhwJ+c8tr8QYET0RxhlTOwLPkpIUK2vC7D AlcnYNQ8GqPpOMalK2grO7cSZciDRIlHfuG7nq5AATSrl3qs0nIY13VbFq5VEG4X UAokXAR134+dxegaON8wWiL0rjomWG1QwD4jtrPOrSSMkIulV7JLB3d/PFyjj2PS +g3Zzci4sa2OfCsLo7s3MROSdhjB/SFwAo1p5P/0EsJipYLMYPHziT7Z3cQT6TK5 UDgax0pXJ2DVTA+m9KPESL2weadIZWtaU+wRIYdxi4JU2y1a7/LjPLFefl9SqN8U dLh8I4xy1YAiT+FRV010ZCJvypE25RTXtFsUWz6MgADvmVhDoo9wSBrK1WxlvtGY 6MB7JSXNBFNrQEwgA15v1mHxSkmrHqiGIqWDT0zULzdQ/1axuQ54Iw9JKlMJLpmL HeTLwCOWi52x03arncZ3toby7DQFweZ2aJnIc5aLxVvejRf/miE= =tqXx -----END PGP SIGNATURE-----
