Debian Package Tracker
Register | Log in
Subscribe

cockpit-machines

Cockpit user interface for virtual machines

Choose email to subscribe with

general
  • source: cockpit-machines (main)
  • version: 356-1
  • maintainer: Utopia Maintenance Team (archive) (DMD)
  • uploaders: Michael Biebl [DMD] – Martin Pitt [DMD]
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 288-1
  • old-bpo: 332-1~bpo12+1
  • stable: 332-1
  • stable-bpo: 356-1~bpo13+1
  • testing: 356-1
  • unstable: 356-1
versioned links
  • 288-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 332-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 332-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 356-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 356-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • cockpit-machines
action needed
Marked for autoremoval on 12 October due to falcosecurity-libs, llvm-toolchain-19, nbclient, sos, spirv-llvm-translator-19, wireshark: #1084954, #1095866, #1124069, #1124098, #1133251, #1142268, #1142865, #1142869, #1144924, #1145338, #1145413, #1145981, #1146020, #1147338 high
Version 356-1 of cockpit-machines is marked for autoremoval from testing on Mon 12 Oct 2026. It depends (transitively) on falcosecurity-libs, llvm-toolchain-19, nbclient, sos, spirv-llvm-translator-19, wireshark, affected by #1084954, #1095866, #1124069, #1124098, #1133251, #1142268, #1142865, #1142869, #1144924, #1145338, #1145413, #1145981, #1146020, #1147338. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-12 Last update: 2026-09-21 05:30
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-92745: A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
  • CVE-2026-92747: A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
  • CVE-2026-92768: A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.
Created: 2026-09-19 Last update: 2026-09-20 17:48
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-92745: A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
  • CVE-2026-92747: A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
  • CVE-2026-92768: A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.
Created: 2026-09-19 Last update: 2026-09-20 17:48
3 security issues in bookworm high

There are 3 open security issues in bookworm.

3 important issues:
  • CVE-2026-92745: A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
  • CVE-2026-92747: A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
  • CVE-2026-92768: A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.
Created: 2026-09-19 Last update: 2026-09-20 17:48
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-92745: (needs triaging) A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
  • CVE-2026-92747: (needs triaging) A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
  • CVE-2026-92768: (needs triaging) A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-19 Last update: 2026-09-20 17:48
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-08-30 10:34
news
[rss feed]
  • [2026-09-04] Accepted cockpit-machines 356-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-09-01] cockpit-machines 356-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-30] Accepted cockpit-machines 356-1 (source) into unstable (Martin Pitt)
  • [2026-08-03] Accepted cockpit-machines 355-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-08-03] cockpit-machines 355-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-31] Accepted cockpit-machines 355-1 (source) into unstable (Martin Pitt)
  • [2026-06-03] Accepted cockpit-machines 353-3~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-06-03] cockpit-machines 353-3 MIGRATED to testing (Debian testing watch)
  • [2026-05-31] Accepted cockpit-machines 353-3 (source) into unstable (Martin Pitt)
  • [2026-05-31] Accepted cockpit-machines 353-2 (source) into unstable (Martin Pitt)
  • [2026-05-31] cockpit-machines 353-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-29] Accepted cockpit-machines 353-1 (source) into unstable (Martin Pitt)
  • [2026-04-12] Accepted cockpit-machines 351-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-04-12] cockpit-machines 351-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-09] Accepted cockpit-machines 351-1 (source) into unstable (Martin Pitt)
  • [2026-03-22] Accepted cockpit-machines 350-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-03-21] cockpit-machines 350-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-19] Accepted cockpit-machines 350-1 (source) into unstable (Martin Pitt)
  • [2026-02-19] Accepted cockpit-machines 348-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-02-19] cockpit-machines 348-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-11] Accepted cockpit-machines 348-1 (source) into unstable (Martin Pitt)
  • [2026-01-31] Accepted cockpit-machines 347-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-01-31] cockpit-machines 347-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-29] Accepted cockpit-machines 347-1 (source) into unstable (Martin Pitt)
  • [2025-12-21] Accepted cockpit-machines 346-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2025-12-20] cockpit-machines 346-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-18] Accepted cockpit-machines 346-1 (source) into unstable (Martin Pitt)
  • [2025-11-29] Accepted cockpit-machines 345-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2025-11-29] cockpit-machines 345-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted cockpit-machines 345-1 (source) into unstable (Martin Pitt)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 96)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 356-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing