[ubuntu/resolute-security] keystone 2:29.0.0-0ubuntu1.4 (Accepted)

John Breton john.breton at canonical.com
Wed Sep 30 12:22:18 UTC 2026


keystone (2:29.0.0-0ubuntu1.4) resolute-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via EC2 credential token misuse
    - debian/patches/Ban-ec2credential-tokens-from-Keystone-API.patch: Ban
      ec2credential tokens from Keystone API in
      keystone/server/flask/request_processing/middleware/auth_context.py,
      keystone/tests/unit/test_contrib_ec2_core.py.
    - d/p/auth-encode-ec2credential-and-oauth2-credential-in-the-method-
      bitmask.patch: auth: encode ec2credential and oauth2_credential in the
      method bitmask in keystone/auth/plugins/core.py,
      keystone/tests/unit/auth/plugins/test_core.py, releasenotes/notes/reserve-
      pseudo-method-bits-404f8c553e033246.yaml.
  * debian/patches/fix-test-state-cleanup.patch: Fix test state cleanup. Dirty
      test state was causing tests to fail if they were run in a specific order
      in keystone/tests/unit/ksfixtures/backendloader.py.
  * SECURITY UPDATE: privilege escalation via delegated tokens on trust
      and credential endpoints
    - debian/patches/CVE-2026-80182.patch: trusts, oauth1, app-creds: reject
      delegated tokens across all endpoints in
      keystone/api/_shared/delegation.py, keystone/api/os_oauth1.py,
      keystone/api/trusts.py, keystone/api/users.py, keystone/conf/auth.py,
      keystone/tests/unit/test_v3_application_credential.py,
      keystone/tests/unit/test_v3_oauth1.py,
      keystone/tests/unit/test_v3_trust.py,
      releasenotes/notes/bug-2153453-6f2a1d9e0c7b4a83.yaml.
    - CVE-2026-80182
  * SECURITY UPDATE: privilege escalation via delegated token reauthentication
    - debian/patches/CVE-2026-80184.patch: auth: reject delegated tokens from
      token-method reauthentication in keystone/auth/plugins/token.py,
      keystone/tests/unit/test_v3_auth.py,
      releasenotes/notes/bug-2158538-delegated-token-rescope-a1b2c3d4e5f6.yaml,
      keystone/tests/unit/test_contrib_ec2_core.py.
    - CVE-2026-80184
  * SECURITY UPDATE: unauthorized domain role assignment information exposure
    - debian/patches/CVE-2026-80183.patch: Prevent unauthorized project-scoped
      assignment list in keystone/common/policies/role_assignment.py,
      keystone/tests/protection/v3/test_assignment.py,
      releasenotes/notes/bug-2154645-role-assignment-tree-domain-
      bypass-f126c413bd62c375.yaml.
    - CVE-2026-80183

Date: 2026-09-28 18:28:18.396584+00:00
Changed-By: Isabel Garcia <isabel.garcia at canonical.com>
Signed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/keystone/2:29.0.0-0ubuntu1.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list