Your message dated Tue, 28 Jul 2026 13:51:56 +0000
with message-id <[email protected]>
and subject line Bug#1142857: fixed in ironic-python-agent 11.5.0-4
has caused the Debian Bug report #1142857,
regarding ironic-python-agent: CVE-2026-66138
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142857: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142857
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ironic-python-agent
Version: 11.5.0-3
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for ironic-python-agent.

CVE-2026-66138[0]:
| In OpenStack Ironic Python Agent through 11.6.0, a project-scoped
| user with the manager role can achieve arbitrary code execution on a
| running Ironic-Python-Agent via a maliciously constructed
| configuration, because the value of ntp_server is passed to a shell.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66138
    https://www.cve.org/CVERecord?id=CVE-2026-66138
[1] https://www.openwall.com/lists/oss-security/2026/07/23/5
[2] https://bugs.launchpad.net/ironic-python-agent/+bug/2160050

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: ironic-python-agent
Source-Version: 11.5.0-4
Done: Thomas Goirand <[email protected]>

We believe that the bug you reported is fixed in the latest version of
ironic-python-agent, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated ironic-python-agent 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 28 Jul 2026 15:16:29 +0200
Source: ironic-python-agent
Architecture: source
Version: 11.5.0-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1142857 1142943
Changes:
 ironic-python-agent (11.5.0-4) unstable; urgency=medium
 .
   * CVE-2026-66138 / OSSA-2026-027: command execution via unsanitized config.
     Applied upstream patch: "fix NTP command handling" (Closes: #1142857).
   * CVE-2026-54422 / OSSA-2026-028: credential extraction from Ironic Python
     Agent via malicious container. Applied upstream patch: "Do not expose
     registry pull secret to bootc container" (Closes: #1142943).
Checksums-Sha1:
 fd5c9baa04cb6a82e8d7684350df8338e967d5a0 2661 ironic-python-agent_11.5.0-4.dsc
 98cac752aef71d46cb227187b35bdd3545e46deb 14028 
ironic-python-agent_11.5.0-4.debian.tar.xz
 22fa46a3965266fcf692a135dbfc98ddd939408b 12539 
ironic-python-agent_11.5.0-4_amd64.buildinfo
Checksums-Sha256:
 1a5e506fd4bc43adef973f27b66cfee540b29fcf94d3527272cbf49c64fb592d 2661 
ironic-python-agent_11.5.0-4.dsc
 9d6d64f5d58a0b4ebc6ae957b1c10dd30c3589396144d5ae97a9d07bb27399e1 14028 
ironic-python-agent_11.5.0-4.debian.tar.xz
 97c5fed57794a146afc4776cd8090c5b01bab28121d35f55a7314b278471f9a2 12539 
ironic-python-agent_11.5.0-4_amd64.buildinfo
Files:
 a9ed002b92054020aaa5538af931f608 2661 net optional 
ironic-python-agent_11.5.0-4.dsc
 6e66c013fba09ea450a1a354d71e59ce 14028 net optional 
ironic-python-agent_11.5.0-4.debian.tar.xz
 0048c2b5716afaa51ee1f3db008186ab 12539 net optional 
ironic-python-agent_11.5.0-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmposSQACgkQ1BatFaxr
Q/4XUQ//aYH6iIoP84TU184FEhuFIeyBVQ2aCbjjnwMCKNGISYHtw05LisuVFbZY
GXOmm5suq93iPI39QvKY6dfP9CrEWyl8jzTn/9FkdpUvJYTdnx9R0oCQLd/1zAm4
V1uN9X4CyNExfmykV8v6aC8VlWIpo5Gz2HVcn+tV8Tc8AVGQ0B+OOel60QLTICCf
31pmQfu5Orbi7gyzvTwY11CuAkxK+zDbBWO6XSfsU3RxDIms/AsEb0hMc8Ak1YFi
/Eihs3BSk+r1Weox0BebdVLSUhKRyqaSOaW9DHSPLD1KI0vQjzSAMoV5Kvmj/eWS
ZrBOfhxvHApee5rxiyF2VPUuMZNPNr1xeJ9oXwrsI2SXkOJU2TdqdY6Nn32IjYuO
Qha9A0lMKmf9AErW006YwXb7wgaoVsnGJEjaOBBWQMCGdTtvmV3Up1ZHGvMwtbFQ
ssdM0W/SSYjRSYciLRWtGQHCWlvrsGFd7+ppqucevMz5MjqWsc+po6OfZ/eOM3hF
wr+eqTw1ursIKTeTipU+trCJblJzzxk3wdKigcWOli9tL5Lj725t26IB5dMY31dW
W5VnTOk5YGmiqYOo1dGVqrEOafu+g9vTTdjzkEiO2NRPT+97bXZU7TmfvJ8NtViB
ZPDvI1jQov9Ap64c4pJZV3Fp8IUY+Q6k2nausIWuS8/sXPy2Ig0=
=hddu
-----END PGP SIGNATURE-----

Attachment: pgp2dxtKfzf3J.pgp
Description: PGP signature


--- End Message ---

Reply via email to