#1144568 trixie-pu: package nova/2:31.0.0-6+deb13u2 (CVE-2026-46448, OSSN-0101)

#1144568#5
Date:
2026-08-16 18:59:39 UTC
From:
To:
Dear release team,

[ Reason ]
I'd like to update Nova to address CVE-2026-46448 / OSSA-2026-022
and OSSN-0101 (see bugs #1140149 and #1142113).

The security team informed me that they prefer for these fixes to be
pushed through p-u.

[ Impact ]
CVE-2026-46448 / OSSA-2026-022: Nova scheduler hint injection bypasses
Placement resource claims and scheduling constraints.

OSSN-0101: Nova console WebSocket proxy Origin allow-list poisoning.

[ Tests ]
Building the Nova package includes running 16742 tests, some of which
were added specifically for the above fixes. On top of this, we've been
running the patched pacakges (truth: in another OpenStack release) in
production. Also, I'm constantly running the upstream functional tests
suite.

[ Risks ]
Patches are very small, if one doesn't consider new tests. It's narly
one-liners.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
2 patches.

Please allow me to upload:
nova_31.0.0-6+deb13u3_source.changes
to Trixie p-u.

Cheers,

Thomas Goirand (zigo)