[ubuntu/resolute-security] cyborg 16.0.0-2ubuntu0.1 (Accepted)
John Breton
john.breton at canonical.com
Tue Jun 9 15:58:45 UTC 2026
cyborg (16.0.0-2ubuntu0.1) resolute-security; urgency=medium
* SECURITY UPDATE: Authentication Bypass
- d/p/CVE-2026-40213_CVE-2026-
40214_1_Use_common_checks.check_policy_json_from_oslo.upgradecheck.p
atch:
- d/p/CVE-2026-40213_CVE-2026-40214_2_Fix_cyborg-
status_upgrade_check_tests.patch:
- d/p/CVE-2026-40213_CVE-2026-40214_3_Fix_rule-
allow_policy_bypass_on_device_deployable_attribute_APIs.patch:
- d/p/CVE-2026-40213_CVE-2026-
40214_4_Set_project_id_on_ARQ_creation_and_binding.patch:
- d/p/CVE-2026-40213_CVE-2026-
40214_5_Refactor_session_handling_and_align_test_contexts.patch:
- d/p/CVE-2026-40213_CVE-2026-
40214_6_Add_project_id_backfill_for_existing_ARQs.patch:
- d/p/CVE-2026-40213_CVE-2026-40214_7_Enforce_project-
scoped_access_for_ARQs.patch:
- d/p/CVE-2026-40213_CVE-2026-
40214_8_Require_service_token_for_bound_ARQ_operations.patch:
- CVE-2026-40213
Date: 2026-06-04 13:39:18.495077+00:00
Changed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/cyborg/16.0.0-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list