- Package:
- src:ironic
- Source:
- src:ironic
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-06 19:03:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for ironic. CVE-2026-74250[0]: | In OpenStack Ironic before 38.0.1, the autodetect deploy interface | may fail to run cleaning immediately after enrollment with, or | changing to, the autodetect deploy interface. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-74250 https://www.cve.org/CVERecord?id=CVE-2026-74250 [1] https://bugs.launchpad.net/ossa/+bug/2163017 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
FYI, the only affected branch for this CVE was Gazapacho, which I fixed in my non-official backport repository. So, only Testing is currently affected, any other Debian release is ok, and Testing will be fixed when Ironic 39 migrates. Please set the security tracker accordingly. Cheers, Thomas Goirand (zigo)
HI Thomas, Thanks for the update, appreciated! Please be bit more specific, as we have a lot of issues to handle ;-) So researched it again, the upstream issue references https://opendev.org/openstack/ironic/commit/3df2664ef309ec98187d9c2f8af411609ffded78 . I have updated the security-tracker metadata accordingly. Regards, Salvatore