Debian Package Tracker
Register | Log in
Subscribe

ironic

Choose email to subscribe with

general
  • source: ironic (main)
  • version: 1:35.0.1-9
  • maintainer: Debian OpenStack (DMD)
  • uploaders: Thomas Goirand [DMD] – Michal Arbet [DMD]
  • arch: all
  • std-ver: 4.4.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:16.0.3-1
  • oldstable: 1:21.4.4-0+deb12u1
  • old-sec: 1:21.4.4-0+deb12u1
  • old-p-u: 1:21.4.4-0+deb12u1
  • stable: 1:29.0.5-0+deb13u2
  • stable-sec: 1:29.0.5-0+deb13u2
  • testing: 1:35.0.1-8
  • unstable: 1:35.0.1-9
versioned links
  • 1:16.0.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:21.4.4-0+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:29.0.5-0+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:35.0.1-8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:35.0.1-9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ironic-api
  • ironic-common
  • ironic-conductor
  • ironic-doc
  • ironic-novncproxy
  • python3-ironic
action needed
Marked for autoremoval on 05 September due to httpcore, node-ipydatagrid, node-playwright, taskflow, towncrier: #1133642, #1135849, #1138720, #1143321, #1143345, #1143428 high
Version 1:35.0.1-8 of ironic is marked for autoremoval from testing on Sat 05 Sep 2026. It depends (transitively) on httpcore, node-ipydatagrid, node-playwright, taskflow, towncrier, affected by #1133642, #1135849, #1138720, #1143321, #1143345, #1143428. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-01 Last update: 2026-08-10 05:16
A new upstream version is available: 38.0.0 high
A new upstream version 38.0.0 is available, you should consider packaging it.
Created: 2026-08-06 Last update: 2026-08-10 03:30
5 security issues in trixie high

There are 5 open security issues in trixie.

1 important issue:
  • CVE-2026-71201: In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
4 issues left for the package maintainer to handle:
  • CVE-2026-43003: (needs triaging) An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
  • CVE-2026-44918: (needs triaging) OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
  • CVE-2026-54421: (needs triaging) In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
  • CVE-2026-54423: (needs triaging) In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-04-28 Last update: 2026-08-06 17:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-71201: In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
Created: 2026-08-05 Last update: 2026-08-06 17:30
15 security issues in bullseye high

There are 15 open security issues in bullseye.

8 important issues:
  • CVE-2026-43003: An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
  • CVE-2026-44917: OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
  • CVE-2026-44918: OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
  • CVE-2026-46447: OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
  • CVE-2026-48681: OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
  • CVE-2026-54421: In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
  • CVE-2026-54423: In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
  • CVE-2026-71201: In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
7 issues postponed or untriaged:
  • CVE-2024-44082: (postponed; to be fixed through a stable update) In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed version details are: Ironic: <21.4.3, >=22.0.0 <23.0.2, >=23.1.0 <24.1.2, >=25.0.0 <26.0.1; Ironic-python-agent: <9.4.2, >=9.5.0 <9.7.1, >=9.8.0 <9.11.1, >=9.12.0 <9.13.1.
  • CVE-2024-47211: (postponed; to be fixed through a stable update) In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
  • CVE-2025-44021: (postponed; to be fixed through a stable update) OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1.
  • CVE-2026-42510: (postponed; to be fixed through a stable update) OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
  • CVE-2026-42997: (needs triaging) An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
  • CVE-2026-44916: (needs triaging) In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
  • CVE-2026-44919: (needs triaging) In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Created: 2026-06-03 Last update: 2026-08-06 17:30
6 security issues in bookworm high

There are 6 open security issues in bookworm.

5 important issues:
  • CVE-2026-43003: An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
  • CVE-2026-44918: OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
  • CVE-2026-54421: In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
  • CVE-2026-54423: In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
  • CVE-2026-71201: In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
1 issue postponed or untriaged:
  • CVE-2024-47211: (needs triaging) In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
Created: 2024-09-04 Last update: 2026-08-06 17:30
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-05-24 Last update: 2026-08-10 04:30
lintian reports 23 warnings normal
Lintian reports 23 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-06 Last update: 2026-08-06 20:31
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • ironic-doc could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2026-08-09 23:32
debian/patches: 4 patches to forward upstream low

Among the 16 debian patches available in version 1:35.0.1-9 of the package, we noticed the following issues:

  • 4 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-08-06 21:32
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2023-10-07 Last update: 2023-10-07 13:10
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.4.1).
Created: 2020-01-21 Last update: 2026-08-06 16:30
testing migrations
  • excuses:
    • Migration status for ironic (1:35.0.1-8 to 1:35.0.1-9): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for ironic/1:35.0.1-9: amd64: Pass, arm64: Pass, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, loong64: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Pass
    • ∙ ∙ Too young, only 4 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/i/ironic.html
    • ∙ ∙ Not reproduced on amd64 (not a regression): ironic-common, ironic-doc
    • ∙ ∙ Not reproduced on arm64 (not a regression): ironic-common, ironic-doc
    • ∙ ∙ Not reproduced on armhf (not a regression): ironic-common, ironic-doc
    • ∙ ∙ Not reproduced on i386 (not a regression): ironic-common, ironic-doc
    • Not considered
news
[rss feed]
  • [2026-08-06] Accepted ironic 1:35.0.1-9 (source) into unstable (Thomas Goirand)
  • [2026-07-11] ironic 1:35.0.1-8 MIGRATED to testing (Debian testing watch)
  • [2026-07-09] Accepted ironic 1:35.0.1-8 (source) into unstable (Thomas Goirand)
  • [2026-06-24] ironic 1:35.0.1-7 MIGRATED to testing (Debian testing watch)
  • [2026-06-18] Accepted ironic 1:35.0.1-7 (source) into unstable (Thomas Goirand)
  • [2026-06-16] Accepted ironic 1:35.0.1-6 (source) into unstable (Thomas Goirand)
  • [2026-06-11] Accepted ironic 1:21.4.4-0+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-06-11] Accepted ironic 1:29.0.5-0+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-06-11] Accepted ironic 1:29.0.5-0+deb13u2 (source) into stable-security (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-06-11] Accepted ironic 1:21.4.4-0+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-06-11] ironic 1:35.0.1-5 MIGRATED to testing (Debian testing watch)
  • [2026-06-05] Accepted ironic 1:35.0.1-5 (source) into unstable (Thomas Goirand)
  • [2026-05-26] Accepted ironic 1:29.0.5-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-05-24] Accepted ironic 1:21.1.0-3+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Thomas Goirand)
  • [2026-05-23] ironic 1:35.0.1-3 MIGRATED to testing (Debian testing watch)
  • [2026-05-15] Accepted ironic 1:35.0.1-3 (source) into unstable (Thomas Goirand)
  • [2026-05-08] Accepted ironic 1:35.0.1-2 (source) into unstable (Thomas Goirand)
  • [2026-05-07] Accepted ironic 1:35.0.1-1 (source) into unstable (Thomas Goirand)
  • [2026-04-03] ironic 1:35.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-27] Accepted ironic 1:35.0.0-2 (source) into unstable (Thomas Goirand)
  • [2026-03-25] Accepted ironic 1:35.0.0-1 (source) into experimental (Thomas Goirand)
  • [2026-03-16] Accepted ironic 1:34.0.0-1 (source) into experimental (Thomas Goirand)
  • [2026-02-15] ironic 1:32.0.0-7 MIGRATED to testing (Debian testing watch)
  • [2026-02-09] Accepted ironic 1:32.0.0-7 (source) into unstable (Thomas Goirand)
  • [2025-12-02] ironic 1:32.0.0-6 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted ironic 1:32.0.0-6 (source) into unstable (Thomas Goirand)
  • [2025-11-26] Accepted ironic 1:32.0.0-5 (source) into unstable (Thomas Goirand)
  • [2025-11-25] ironic 1:32.0.0-4 MIGRATED to testing (Debian testing watch)
  • [2025-11-20] ironic REMOVED from testing (Debian testing watch)
  • [2025-10-01] Accepted ironic 1:32.0.0-4 (source) into unstable (Thomas Goirand)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 23)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:35.0.0-0ubuntu3
  • patches for 1:35.0.0-0ubuntu3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing