Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66138

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability was found in Ironic-Python-Agent's (IPA) time syncing code. The value of the ntp_server configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. This value can be set in three ways; directly in an operator-created ramdisk, set via kernel command line using Ironic, or passing the parameters via mDNS responder for mDNS enabled installation. For the most common, and highest security risk case, this means a Manager role associated with the project set as node.owner may be able to trigger this vulnerability.

Отчет

Red Hat OpenStack Platform ships ironic-python-agent as part of bare metal provisioning. Deployments using chrony for time synchronization in the IPA ramdisk are affected by this vulnerability. The impact is limited to the bare metal node running the IPA ramdisk; there is no known method for leveraging ramdisk shell access to compromise the Ironic control plane service. In RHOSP 18.0 (Ironic 21.0+), a user with the project-scoped Manager role and node ownership can set kernel command line parameters that include a malicious ipa-ntp-server value. The Manager role is a delegated, limited-scope role introduced in Ironic 21.0.0; a manager-scoped user cannot change base service configuration or templates, cannot access nodes in other projects, and cannot pivot the attack beyond their isolated project scope. In RHOSP 17.1 (Ironic <21.0), the Manager role does not exist. Exploitation requires either a user with the admin role, or manually starting the agent outside of Ironic's context to trigger the mDNS configuration loading path, which is not a default deployment configuration. The mDNS attack vector is related to legacy Kubernetes Native Infrastructure efforts and is not in a standard deployment path.

Меры по смягчению последствий

Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-ironic-agent-rhel9Affected
Red Hat OpenShift Container Platform 4openstack-ironic-python-agentAffected
Red Hat OpenStack Platform 16.2openstack-ironic-python-agentNot affected
Red Hat OpenStack Platform 17.1openstack-ironic-python-agentAffected
Red Hat OpenStack Platform 18.0openstack-ironic-python-agentAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2506676ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration

EPSS

Процентиль: 35%
0.00423
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
8 дней назад

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

CVSS3: 7.2
nvd
8 дней назад

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

CVSS3: 7.2
debian
8 дней назад

In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user ...

CVSS3: 7.2
github
8 дней назад

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

EPSS

Процентиль: 35%
0.00423
Низкий

8.8 High

CVSS3