Dear release team,
[ Reason ]
I'd like to update Nova to address CVE-2026-46448 / OSSA-2026-022
and OSSN-0101 (see bugs #1140149 and #1142113).
The security team informed me that they prefer for these fixes to be
pushed through p-u.
[ Impact ]
CVE-2026-46448 / OSSA-2026-022: Nova scheduler hint injection bypasses
Placement resource claims and scheduling constraints.
OSSN-0101: Nova console WebSocket proxy Origin allow-list poisoning.
[ Tests ]
Building the Nova package includes running 16742 tests, some of which
were added specifically for the above fixes. On top of this, we've been
running the patched pacakges (truth: in another OpenStack release) in
production. Also, I'm constantly running the upstream functional tests
suite.
[ Risks ]
Patches are very small, if one doesn't consider new tests. It's narly
one-liners.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
2 patches.
Please allow me to upload:
nova_31.0.0-6+deb13u3_source.changes
to Trixie p-u.
Cheers,
Thomas Goirand (zigo)