- Package:
- src:octavia
- Source:
- src:octavia
- Submitter:
- Thomas Goirand
- Date:
- 2026-08-19 09:55:02 UTC
- Severity:
- normal
- Tags:
As per upstream announce at: https://security.openstack.org/ossa/OSSA-2026-035.html Date: August 13, 2026 CVE: CVE-2026-74248 Affects: Octavia: <16.0.2, ==17.0.0, ==18.0.0 Description: Chen YuXiang with the Institute of Computing Technology, Chinese Academy of Sciences, reported a vulnerability in Octavia quality of service (QoS) policy authorization. By associating another project’s QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected. Errata: MITRE assigned CVE-2026-74248 after intial publication. Patches: https://review.opendev.org/1000296 (2025.1/epoxy) https://review.opendev.org/1000295 (2025.2/flamingo) https://review.opendev.org/1000094 (2026.1/gazpacho) https://review.opendev.org/998935 (2026.2/hibiscus (development)) Credits: Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-74248) References: https://launchpad.net/bugs/2161500 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74248 OSSA History: 2026-08-17 - Errata 1 2026-08-13 - Original Version
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/e9115efb8e54a6ec3ed106cb1adbb9eca621db5c ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/3db69c6cf356533d9507abff734bf14816a50cf9 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/45c8667e696b337706d2c96f1add58049f7c572b ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/7db19d87480f72efd28d0c459a8e4e66c9e49018 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/4142b5c684059cfcef66d7829a396d933641e377 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/a7fb33e030f34b34499045ccc84d63123a32e62b ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/2636488d5fa73d8c2a1546fb9bfdaf895774195f ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/be76c9cbc1587fd131b17525cc6d5e7080976979 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/63b79c0ac2c15ee60e606c7d929a9a76f36e1a4f ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/0e87da7733ef0fb88c5695468674c1d3f9d3b773 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/5ae3be2e7b731923c52d47887b6fc474d18d3aeb ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/abd8ac0e30ce855d2f0bf44a321f37d45d7ab8b3 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/7f1ce7358a68e94651af87e1217a83599e4b76fc ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
Hello, Bug #1144814 in octavia reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/octavia/-/commit/8e55dde8b3d180867a5b4d5e3998e205498d0627 ------------------------------------------------------------------------ * CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock. Applied upstream patch: "Fix QoS policy validation to use request context". (Closes: #1144814). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144814
We believe that the bug you reported is fixed in the latest version of
octavia, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144814@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated octavia package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 19 Aug 2026 11:06:24 +0200
Source: octavia
Architecture: source
Version: 18.0.0-3
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144814
Changes:
octavia (18.0.0-3) unstable; urgency=high
.
* CVE-2026-74248 / OSSA-2026-035: Unauthorized QoS policy deletion lock.
Applied upstream patch: "Fix QoS policy validation to use request context".
(Closes: #1144814).
Checksums-Sha1:
06b11d7a3b9ff23640bceec03c32a6f00bab7238 4216 octavia_18.0.0-3.dsc
77f40477eb4e732d1e7caace2b0b8999b5cf2699 21668 octavia_18.0.0-3.debian.tar.xz
0d12af0f49a52dcb3056516124e46077e5e6caf0 20109 octavia_18.0.0-3_amd64.buildinfo
Checksums-Sha256:
0c5eb62fe3f7dee2834e1a03d5a5a59d2603eae8125c3b009be77930886a4675 4216 octavia_18.0.0-3.dsc
fc028dd4553b905699e3d12fed1c75e35c1fd1310eefd99320307a5aa4583d5d 21668 octavia_18.0.0-3.debian.tar.xz
e1f07a0dfc00084eb3ff3f99551cc42d61cc8865bfe393e4ab4b7f23878fcb0b 20109 octavia_18.0.0-3_amd64.buildinfo
Files:
b76838e0484a84a6a237195e7324fb45 4216 net optional octavia_18.0.0-3.dsc
48a512c40982c11533b1a4523a7b5769 21668 net optional octavia_18.0.0-3.debian.tar.xz
5b1e54d01cd8766ffb4d1efc65638ec0 20109 net optional octavia_18.0.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqFdKgACgkQ1BatFaxr
Q/6VpBAAjfispCvsYN/D2enY+k+6NNuN4YU1lUQMcxouQXh064usng2PAOSs5PAQ
vgT8vZ6cdOlWkIiwl+w+2z45anhmz4ar1uCW9T6FtLuXF1elw/prBeluaC4Q6ito
AC7189U+yah40hyXrD6e4n5Jb3Oh3LqbEgXW20I9ZXLmM/hQP6hPqqRX2xHYEqjL
nepCOAKFgM4y5xxo9TToBb608Zsg3FSLvwruVFA+DHxfhKOXjEZjxSlxEfpw7YL4
owpMtcSPG8SV2sVAYIYe2aYmJ6UTfJ2v/Ac3+Ob/ZEe+ET4jJgn77zHdxxXKnMX0
sczc++FxffXaVW7n1x0LyNCALlYXUXUYKSacp0FvsLLZr7tGfpxELO3xPY3zEyTA
6ef7V2TI1Cc1xru79XvCgkmSDiq2Sig3ksSkybcHLPvvwHAl6uPHnQIjrcvJiJCo
WS194dlOkUnRNoOuUDeZgO4+kd6gy1HRCeq1XXFtN+8vwhFTSbNsguZp1Gyufy/c
g9qrITosUPefgcGsLd+09G8H2+uI6IzxbjeQUsj60d3OuEci+lKbX8CpbWEsLtM3
X5U6XDKLN1jrWIYOlSx9RINc7p/VMFn+S5H6ICOMotf4qHI0G0mnT9TKBNwDm21q
ZEPjisAK22aZWKRvEMuBfA2z5jIqkW5uGNmYky3n9aASwl495tM=
=GF4S
-----END PGP SIGNATURE-----