Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN776
_____________________________________________________________________

DATE                : 24/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Ironic-python-agent versions
                         prior to 10.2.3, 11.2.1, 11.5.1.
 
=====================================================================
https://security.openstack.org/ossa/OSSA-2026-027.html
https://security.openstack.org/ossa/OSSA-2026-028.html
_____________________________________________________________________


OSSA-2026-027: Command execution via unsanitized config

Date:     July 23, 2026
CVE:      CVE-2026-66138

Affects

    Ironic-python-agent: >=6.0.0 <10.2.3, >=11.0.0 <11.2.1,
     >=11.3.0 <11.5.1, ==11.6.0

Description

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software
Technology) from the Metal3.io Security Team reported a vulnerability
in Ironic-Python-Agent’s (IPAs) time syncing code.

The value of the ntp_server configuration option is inserted into a
shell command without sanitization. This command is run as root very
early in the IPA startup flow, allowing an attacker to run arbitrary
commands as root.

This value can be set in three ways; directly in an operator-created
ramdisk, set via kernel command line using Ironic, or passing the
parameters via mDNS responder for mDNS enabled installation. For the
most common, and highest security risk case, this means a Manager
role associated with the project set as node.owner may be able to
trigger this vulnerability.


Errata

CVE-2026-66138 has been assigned for this vulnerability.


Patches

    https://review.opendev.org/998492 (2023.1/antelope (unmaintained))

    https://review.opendev.org/998491 (2024.1/caracal (unmaintained))

    https://review.opendev.org/998490 (2025.1/epoxy)

    https://review.opendev.org/998489 (2025.2/flamingo)

    https://review.opendev.org/998488 (2026.1/gazpacho)

    https://review.opendev.org/998486 (2026.2/hibiscus (development))

    https://review.opendev.org/998483 (Bugfix/11.3)

    https://review.opendev.org/998482 (Bugfix/11.4)

    https://review.opendev.org/998487 (Bugfix/11.6)


Credits

    Dmitry Tantsur from Red Hat

    Tuomo Tanskanen from Ericsson Software Technology


References

    https://launchpad.net/bugs/2160050

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66138


Notes

    Branches 2024.1/caracal and 2023.1/antelope are unmaintained and
patches are provided as a courtesy.

    Bugfix branches will receive patches in git but will not receive
an updated release.

    While root access to a node running an Ironic workflow has security
implications for that specific node, there is no known method for
turning node ramdisk shell access into a full compromise of the Ironic
service.


OSSA History

    2026-07-24 - Errata 1

    2026-07-23 - Original Version

_____________________________________________________________________


OSSA-2026-028: Credential extraction from Ironic Python Agent via
malicious container

Date:

    July 23, 2026
CVE:

    CVE-2026-54422

Affects

    Ironic-python-agent: >=10.2.0 <10.2.3, >=11.0.0 <11.2.1,
>=11.3.0 <11.5.1

Description

Yuliang Xiao reported a vulnerability in Ironic Python Agent’s
bootc container deployment support. A malicious container can
extract the secrets used to fetch from the OCI registry on
deployment. Operators can fix this issue by applying the
provided patches or completely disabling the bootc deploy_interface
on their Ironic conductors. Any Ironic user with the ability to
deploy arbitrary containers from the bootc deploy_interface can
exploit this.


Patches

    https://review.opendev.org/998485 (2025.1/epoxy)

    https://review.opendev.org/998484 (2025.2/flamingo)

    https://review.opendev.org/998481 (2026.1/gazpacho)

    https://review.opendev.org/998479 (2026.2/hibiscus (development))

    https://review.opendev.org/998494 (Bugfix/11.3)

    https://review.opendev.org/998493 (Bugfix/11.4)

    https://review.opendev.org/998480 (Bugfix/11.6)


Credits

    Yuliang Xiao ()


References

    https://launchpad.net/bugs/2155826

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54422

Notes

    Ironic Python Agent bugfix branch patches will be available in
git for interested operators. We will not perform an additional
release from these branches.



=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




