#1144458 ironic: CVE-2026-74250

Package:
src:ironic
Source:
src:ironic
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 19:03:03 UTC
Severity:
normal
Tags:
#1144458#5
Date:
2026-08-15 12:04:23 UTC
From:
To:
Hi,

The following vulnerability was published for ironic.

CVE-2026-74250[0]:
| In OpenStack Ironic before 38.0.1, the autodetect deploy interface
| may fail to run cleaning immediately after enrollment with, or
| changing to, the autodetect deploy interface.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-74250
https://www.cve.org/CVERecord?id=CVE-2026-74250
[1] https://bugs.launchpad.net/ossa/+bug/2163017

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144458#10
Date:
2026-10-06 15:08:59 UTC
From:
To:
FYI, the only affected branch for this CVE was Gazapacho, which I fixed
in my non-official backport repository.

So, only Testing is currently affected, any other Debian release is ok,
and Testing will be fixed when Ironic 39 migrates. Please set the
security tracker accordingly.

Cheers,

Thomas Goirand (zigo)

#1144458#15
Date:
2026-10-06 19:01:03 UTC
From:
To:
HI Thomas,

Thanks for the update, appreciated! Please be bit more specific, as we
have a lot of issues to handle ;-)

So researched it again, the upstream issue references
https://opendev.org/openstack/ironic/commit/3df2664ef309ec98187d9c2f8af411609ffded78
.

I have updated the security-tracker metadata accordingly.

Regards,
Salvatore