[ubuntu/noble-security] ironic 1:24.1.1-0ubuntu1.3 (Accepted)

Federico Quattrin federico.quattrin at canonical.com
Thu Jun 11 19:18:41 UTC 2026


ironic (1:24.1.1-0ubuntu1.3) noble-security; urgency=medium

  * SECURITY UPDATE: sanitize kernel_append_params to prevent injection
    - d/p/cve-2026-46447-sanitize-kernel-append-params.patch: Validate
      kernel_append_params against a kernel command line grammar and
      reject malformed parameters. Add disable_kernel_parameter_parsing
      config option.
    - CVE-2026-46447
  * SECURITY UPDATE: disable insecure driver_info pxe_template override
    - d/p/lp2148319-disable-pxe-template-override.patch: Remove direct
      file path support for pxe_template to prevent privilege escalation.
    - CVE-2026-44917
  * SECURITY UPDATE: prevent directory traversal in ISO9660 image handling
    - d/p/lp2148333-directory-traversal-iso9660.patch: Validate ISO9660
      path entries to reject directory traversal attempts in config drive
      ISO images.
    - CVE-2026-48681

Date: 2026-06-05 16:59:28.449599+00:00
Changed-By: Hemanth Nakkina <hemanth.nakkina at canonical.com>
Maintainer: Chuck Short <charles.short at windriver.com>
Signed-By: Federico Quattrin <federico.quattrin at canonical.com>
https://launchpad.net/ubuntu/+source/ironic/1:24.1.1-0ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list