Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43003

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 8.5
EPSS Низкий

Описание

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

A flaw was found in OpenStack ironic-python-agent (IPA). The Ironic Python Agent sometimes executes the grub-install command from within a chroot environment of a deployed partition image. This allows an attacker, by providing a malicious image, to achieve arbitrary code execution within the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-ironic-agent-rhel8Affected
Red Hat OpenShift Container Platform 4openshift4/ose-ironic-agent-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2464306ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image

EPSS

Процентиль: 53%
0.00805
Низкий

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
3 месяца назад

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

CVSS3: 8
nvd
3 месяца назад

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

CVSS3: 8
debian
3 месяца назад

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through ...

CVSS3: 8
github
3 месяца назад

OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere

EPSS

Процентиль: 53%
0.00805
Низкий

8.5 High

CVSS3