Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54422

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

A flaw was found in OpenStack ironic-python-agent's bootc container deployment support. During bootc image deployment, the OCI registry pull secret was exposed to tenant-controlled container code running with host PID namespace visibility. A malicious bootc container image could read the operator's registry credentials from the host filesystem via /proc/1/root, leading to credential disclosure. This could allow a project-scoped tenant to extract shared operator registry credentials, potentially affecting multiple nodes and projects.

Отчет

Red Hat OpenStack Platform ships ironic-python-agent as part of its bare metal provisioning infrastructure. Deployments that use the bootc deploy_interface are affected by this vulnerability when operator-sourced registry pull secrets are used. Deployments that do not use the bootc deploy_interface, or that do not use authenticated container registries, are not affected. The bootc deployment feature was introduced in more recent versions of ironic-python-agent. Older versions of Red Hat OpenStack Platform that ship ironic-python-agent versions prior to 10.2.0 are not affected as they do not contain bootc deployment support.

Меры по смягчению последствий

Operators can disable the bootc deploy_interface on their Ironic conductors by setting 'disable_bootc_deploy = true' in the ironic-python-agent configuration. Additionally, operators should avoid using operator-sourced registry pull secrets (driver_info.image_pull_secret or [deploy] image_server_user/password) with the bootc deploy_interface until the fix is applied. If the bootc deploy_interface must remain enabled, restrict which users can deploy arbitrary container images by limiting access to the baremetal provisioning API.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-ironic-agent-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openstack-ironic-python-agentFix deferred
Red Hat OpenStack Platform 16.2openstack-ironic-python-agentNot affected
Red Hat OpenStack Platform 17.1openstack-ironic-python-agentNot affected
Red Hat OpenStack Platform 18.0openstack-ironic-python-agentNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2501234ironic-python-agent: ironic-python-agent: Credential extraction from bootc container deployment via /proc/1/root

EPSS

Процентиль: 3%
0.00124
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
12 дней назад

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

CVSS3: 5.5
nvd
12 дней назад

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

CVSS3: 5.5
debian
12 дней назад

In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...

CVSS3: 5.5
github
12 дней назад

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

EPSS

Процентиль: 3%
0.00124
Низкий

6.5 Medium

CVSS3