-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 Aug 2026 10:26:35 +0200 Source: keystone Architecture: source Version: 2:22.0.2-0+deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: Debian OpenStack <team+openstack@tracker.debian.org> Changed-By: Thomas Goirand <zigo@debian.org> Closes: 1145669 1145816 Changes: keystone (2:22.0.2-0+deb12u4) bookworm-security; urgency=medium . * CVE-2026-80184: Delegation bypass in trust, OAuth1, and application credential operations. * CVE-2026-80182: Tokens obtained via application credential or EC2 credential authentication can escape their intended project scope through token-method reauthentication. An application-credential token scoped to one project can be exchanged via POST /v3/auth/tokens with no explicit scope, causing Keystone to issue a new token scoped to the owner's default project. For EC2-derived tokens the bypass is broader: because they carry no delegation markers, they can rescope to any project where the underlying user has role assignments. * Add new patches (Closes: #1145669): - CVE-2026-80182_CVE-2026-80184_1_Block_app_credential_token_resco....patch - CVE-2026-80182_CVE-2026-80184_2_Ban_ec2credential_tokens_from_Ke....patch - CVE-2026-80182_CVE-2026-80184_3_auth_encode_ec2credential_and_oa....patch - CVE-2026-80182_CVE-2026-80184_4_trusts_oauth1_app-creds_reject_d....patch - CVE-2026-80182_CVE-2026-80184_5_auth_reject_delegated_tokens_fro....patch - CVE-2026-80182_CVE-2026-80184_6_fix-unit-tests.patch * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch Checksums-Sha1: 5c1cbd366723c2778cfe2cfdea14413efc9c0ee0 3565 keystone_22.0.2-0+deb12u4.dsc 0082bb40f85f63bd5bf7d67aa7d0089a229090a3 1055220 keystone_22.0.2.orig.tar.xz 1f2678bee87d73a9b35ced17da201913aeb53535 88072 keystone_22.0.2-0+deb12u4.debian.tar.xz a147d5a494d6712cd3bfb1062d348683fda9ceda 18303 keystone_22.0.2-0+deb12u4_amd64.buildinfo Checksums-Sha256: bcb1d02913be339de6a2dfe75336179a06f6d073e29ac03f449a3b7fb84401c4 3565 keystone_22.0.2-0+deb12u4.dsc a30c128c86b0d53be1998fb9babd49956d74fd9130ff198dddd9f24c01b0c22f 1055220 keystone_22.0.2.orig.tar.xz 2e678642b5d20d40952c598215c72fe1767b759dcb1c51de766d164f98218322 88072 keystone_22.0.2-0+deb12u4.debian.tar.xz 2d1c861ffb638e7a9e234066da91d44f10dfcc10fac8cc23bc36c53dd96b07d3 18303 keystone_22.0.2-0+deb12u4_amd64.buildinfo Files: 241897bf071be1290933dc0fa2186370 3565 net optional keystone_22.0.2-0+deb12u4.dsc 60a14722d5ffdf9c7893a4568f3e25a9 1055220 net optional keystone_22.0.2.orig.tar.xz 9b801bf2831ae240b09d63d85a580273 88072 net optional keystone_22.0.2-0+deb12u4.debian.tar.xz 242bcd69c15176e3d64f58fd69b8e94b 18303 net optional keystone_22.0.2-0+deb12u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqX6u0ACgkQ1BatFaxr Q/6+cQ/9H/aZ4mmFi0V1MtJjijmFLB4QYWaYYm2dA5zkC2TOadHgbHZSYSdgYAnj q9JcmFKmTLSN8dmW42GLH7rWWyEnRiY7DfaXGFZF1iXS56wDdUgsiVNXGbYwbaX2 HONBZPbEvTRXVoSC1PM0A15viDBu/YhFs0R0vQW9rFMLUGGniLXt3iPNG8sNvjjK gI5EGdCYPrqsePv0u5nrdUZigav/2mt7+Liex9lbUGC5PgphSIHSxPYNaNwhKEgP xj4/YGaFkTP5kayoQrYB8DViCLreoo8QQNwkU+Pr+khze6jjnhj9qRwLOOw9trlM EDZqGtYg3w7/W//gtxp0bhtNlsn8aaG6OZyxDUA14iGTK5rqDXfz//qAwkYUIDlC GpQLCvEOfTWjlD+Mvp8l/JZkMw9/R4W1JjFvITuCaKh/a+1jx7s4aTADs/45OEo2 CoAtjOBwQ6H4+YksY94LrHu1Z3d28EcedSOhJJnnWTzYOKYmDOJP8zZBKa+CLWbI +BKbqUU4MNTXHPGpSyNgZVZBiz8Dkoz18cVh4osJ5tlYScQ4jVg3so/OwoOyflKT s91TV3YK/I2a60+niIWpSKU9LhjYoOTu0e1A4BXA+xNDmA4UdYUlInmtPPTEjXbv 6wiiVAyeabVg0bOwZUpNqHp84WEuz6YYKJyf8hoU6Cku5K5kTcw= =4jxq -----END PGP SIGNATURE-----