-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 12 May 2025 09:03:43 +0200 Source: ironic Architecture: source Version: 1:29.0.0-6 Distribution: unstable Urgency: high Maintainer: Debian OpenStack <team+openstack@tracker.debian.org> Changed-By: Thomas Goirand <zigo@debian.org> Closes: 1104964 Changes: ironic (1:29.0.0-6) unstable; urgency=high . * CVE-2025-44021: Ironic fails to restrict paths used for file:// image URLs. Add upstream patch: OSSA-2025-001_Disallow+unsafe_image_file_paths.patch. (Closes: #1104964). Checksums-Sha1: b4a6cc3055f231ec9776bf3eff42928c5203668a 4064 ironic_29.0.0-6.dsc 15172b4f766d0fe8d915e4d26455aee962afee15 22412 ironic_29.0.0-6.debian.tar.xz 97cb81e5b74fdc120bbd1651387225e1027d0ce6 22303 ironic_29.0.0-6_amd64.buildinfo Checksums-Sha256: 717c17472686985536732c82c56a2847c98532187737904ba60254c84585ddc3 4064 ironic_29.0.0-6.dsc 331ee26a5ffc6fde97b2306688b77f00267e025081e9190ad389ce326db9f96e 22412 ironic_29.0.0-6.debian.tar.xz 270f3e0f286a0c1d4ab445e3ab0072d0779ee9031426321e6e354056a73476bf 22303 ironic_29.0.0-6_amd64.buildinfo Files: 60765b2c869766bc5d73502a2db70716 4064 net optional ironic_29.0.0-6.dsc 2d9c97aba9f561bf643badd17154ccf5 22412 net optional ironic_29.0.0-6.debian.tar.xz 613b2119264266c0a33a9a86176a142d 22303 net optional ironic_29.0.0-6_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmghoeMACgkQ1BatFaxr Q/7yiw/+O54HxQlh2rZpaoVX0EQFGj6ZgVcADgnMC26pHP4rFGLt612dZVRXwJ6h OzeRi1XbJm0PwWNFxzyYbrwnDqZYv+JU4Xq/BL9wOy6RHcTuhdomjfbBcmBFUqSx rqc1zNtHpAJKkr00uI932VNt77Gda1pq9sVO2KsSqFxkBjglxTVEeE8UKzpGOGjs 04CBD15MQOQ914OuqW9etZqOpHFfqqhx26li6opszSsATAKIOIrjqV5rb70JPcxQ W9HLbm4Ho5APW0+XZBGKqFgIw1pp7nrQwrMLM3XmAfIFzdCRTiW/OlJnreZwongD 37BW3w3cILu7jI1ibzqDR4ZYIeyEIWmaimoo5NYKVm7mB5XzOoD6EKy24l5Dg8D6 N1u1QUsQQqhX1hYwNfxXuVTvXlMy/KzZDp+3erOltbJ0ftxZ5SLPcelysJOU5nWM os+x3O1Htf2dQyRM6lozTPPo31DbRlo+uALd1FJDk9MMLTTTw8Ex9eEdFtYexiQE MCxRFlkY4Ce4D1wl3TVnMyo+yCx7KAeqTlYHgW8/u+rLENq7q3tuBXRdUAR8XTvj KGySvmlq3SbEda7cF3rTQrSeGSANpyEwtgm3egF8lFnZfRyggoRAKKq7QlE5wNfg XX/CD6av7VKmUwRFq0tm8HlSN5N/n1xBAHzuoh3j9XCK3AyDdtI= =KmKp -----END PGP SIGNATURE-----