Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-74250

Опубликовано: 14 авг. 2026
Источник: redhat
EPSS Низкий

Описание

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

A flaw was found in OpenStack Ironic. The autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. This can lead to operational issues where necessary cleaning procedures are not executed.

Отчет

A flaw was found in OpenStack Ironic. When using the autodetect deploy interface, the cleaning step may be skipped immediately after a node is enrolled or when changing to the autodetect deploy interface. This could allow data from a previous tenant to remain on the hardware, potentially exposing sensitive information to subsequent tenants. This vulnerability was introduced in ironic version 32.0.0 and is fixed in versions 35.0.2 and 38.0.1.

Меры по смягчению последствий

Use an explicit deploy interface (such as 'direct' or 'iscsi') instead of the 'autodetect' deploy interface. Alternatively, manually trigger cleaning on nodes after enrollment or interface changes to ensure previous tenant data is removed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-ironic-rhel9Fix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-ironic-apiNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-ironic-baseNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-ironic-conductorNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-ironic-inspectorNot affected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-ironic-pxeNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2516217ironic: OpenStack Ironic: Autodetect deploy interface fails to run cleaning

EPSS

Процентиль: 17%
0.00254
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
14 дней назад

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

CVSS3: 6.3
nvd
14 дней назад

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

CVSS3: 6.3
debian
14 дней назад

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may ...

CVSS3: 6.3
github
14 дней назад

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

EPSS

Процентиль: 17%
0.00254
Низкий
Уязвимость CVE-2026-74250