#1144459 octavia: CVE-2026-74248

Package:
src:octavia
Source:
src:octavia
Submitter:
Salvatore Bonaccorso
Date:
2026-08-19 09:55:03 UTC
Severity:
normal
Tags:
#1144459#5
Date:
2026-08-15 12:06:07 UTC
From:
To:
Hi,

The following vulnerability was published for octavia.

CVE-2026-74248[0]:
| OpenStack Octavia through 18.0.0 mishandles quality of service (QoS)
| policy authorization. By associating another project's QoS policy
| with an amphora, an authenticated user may prevent deletion of that
| policy. All Octavia deployments are affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-74248
https://www.cve.org/CVERecord?id=CVE-2026-74248
[1] https://www.openwall.com/lists/oss-security/2026/08/13/12
[2] https://bugs.launchpad.net/octavia/+bug/2161500

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144459#14
Date:
2026-08-19 09:34:43 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
octavia, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144814@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated octavia package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 19 Aug 2026 11:06:24 +0200
Source: octavia
Architecture: source
Version: 18.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144814
Changes:
 octavia (18.0.0-3) unstable; urgency=high
 .
   * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock.
     Applied upstream patch: "Fix QoS policy validation to use request context".
     (Closes: #1144814).
Checksums-Sha1:
 06b11d7a3b9ff23640bceec03c32a6f00bab7238 4216 octavia_18.0.0-3.dsc
 77f40477eb4e732d1e7caace2b0b8999b5cf2699 21668 octavia_18.0.0-3.debian.tar.xz
 0d12af0f49a52dcb3056516124e46077e5e6caf0 20109 octavia_18.0.0-3_amd64.buildinfo
Checksums-Sha256:
 0c5eb62fe3f7dee2834e1a03d5a5a59d2603eae8125c3b009be77930886a4675 4216 octavia_18.0.0-3.dsc
 fc028dd4553b905699e3d12fed1c75e35c1fd1310eefd99320307a5aa4583d5d 21668 octavia_18.0.0-3.debian.tar.xz
 e1f07a0dfc00084eb3ff3f99551cc42d61cc8865bfe393e4ab4b7f23878fcb0b 20109 octavia_18.0.0-3_amd64.buildinfo
Files:
 b76838e0484a84a6a237195e7324fb45 4216 net optional octavia_18.0.0-3.dsc
 48a512c40982c11533b1a4523a7b5769 21668 net optional octavia_18.0.0-3.debian.tar.xz
 5b1e54d01cd8766ffb4d1efc65638ec0 20109 net optional octavia_18.0.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqFdKgACgkQ1BatFaxr
Q/6VpBAAjfispCvsYN/D2enY+k+6NNuN4YU1lUQMcxouQXh064usng2PAOSs5PAQ
vgT8vZ6cdOlWkIiwl+w+2z45anhmz4ar1uCW9T6FtLuXF1elw/prBeluaC4Q6ito
AC7189U+yah40hyXrD6e4n5Jb3Oh3LqbEgXW20I9ZXLmM/hQP6hPqqRX2xHYEqjL
nepCOAKFgM4y5xxo9TToBb608Zsg3FSLvwruVFA+DHxfhKOXjEZjxSlxEfpw7YL4
owpMtcSPG8SV2sVAYIYe2aYmJ6UTfJ2v/Ac3+Ob/ZEe+ET4jJgn77zHdxxXKnMX0
sczc++FxffXaVW7n1x0LyNCALlYXUXUYKSacp0FvsLLZr7tGfpxELO3xPY3zEyTA
6ef7V2TI1Cc1xru79XvCgkmSDiq2Sig3ksSkybcHLPvvwHAl6uPHnQIjrcvJiJCo
WS194dlOkUnRNoOuUDeZgO4+kd6gy1HRCeq1XXFtN+8vwhFTSbNsguZp1Gyufy/c
g9qrITosUPefgcGsLd+09G8H2+uI6IzxbjeQUsj60d3OuEci+lKbX8CpbWEsLtM3
X5U6XDKLN1jrWIYOlSx9RINc7p/VMFn+S5H6ICOMotf4qHI0G0mnT9TKBNwDm21q
ZEPjisAK22aZWKRvEMuBfA2z5jIqkW5uGNmYky3n9aASwl495tM=
=GF4S
-----END PGP SIGNATURE-----