oss-sec mailing list archives
OSSA-2026-008: OpenStack Ironic: Command Injection in Ironic IPMI Console Implementations (CVE-2026-42510) - errata 1
From: Goutham Pacha Ravi <gouthampravi () gmail com>
Date: Wed, 29 Apr 2026 17:12:49 -0700
======================================================================= OSSA-2026-008: Command Injection in Ironic IPMI Console Implementations ======================================================================= :Date: April 27, 2026 :CVE: CVE-2026-42510 Affects ~~~~~~~- Ironic: >=4.3.0 <26.1.6, >=27.0.0 <29.0.5, >=30.0.0 <32.0.1, >=33.0.0 <35.0.1
Description ~~~~~~~~~~~Dmitry Tantsur and Tuomo Tanskanen from the Metal3.io Security Team reported a vulnerability in Ironic's IPMI console backends. A project manager for the project marked as a ``node.owner`` can inject arbitrary commands which a conductor executes on console activation. No console backends are enabled by default in Ironic. Only installations which have set ``[conductor]/enabled_console_interfaces`` to enable either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable.
Errata ~~~~~~When the original advisory was published a CVE number was not assigned. CVE-2026-42510 was assigned on 2026-04-29.
Patches ~~~~~~~- https://review.opendev.org/c/openstack/ironic/+/986418 (2023.1/antelope (unmaintained)) - https://review.opendev.org/c/openstack/ironic/+/986417 (2024.1/caracal (unmaintained))
- https://review.opendev.org/c/openstack/ironic/+/986363 (2024.2/dalmatian) - https://review.opendev.org/c/openstack/ironic/+/986362 (2025.1/epoxy) - https://review.opendev.org/c/openstack/ironic/+/986361 (2025.2/flamingo) - https://review.opendev.org/c/openstack/ironic/+/986235 (2026.1/gazpacho) Credits ~~~~~~~ - Dmitry Tantsur from Metal3.io Security Team - Tuomo Tanskanen from Metal3.io Security Team References ~~~~~~~~~~ - https://launchpad.net/bugs/2148331 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42510 Notes ~~~~~ - A CVE request was filed with MITRE on 2026-04-27. - Patches for unmaintained branches are provided as a courtesy. - The ``ipmitool-shellinabox`` console interface is already scheduled for removal from Ironic for lack of security support for shellinabox. Security sensitive operators are strongly encouraged to stop use of this console interface immediately. OSSA History ~~~~~~~~~~~~ - 2026-04-29 - Errata 1 - 2026-04-27 - Original Version -- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html
Attachment:
OpenPGP_0x0638DAD3B82C3988.asc
Description: OpenPGP public key
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
Current thread:
- [OSSA-2026-008] Ironic: Command Injection in IPMI Console Implementations (CVE pending) Jay Faulkner (Apr 27)
- OSSA-2026-008: OpenStack Ironic: Command Injection in Ironic IPMI Console Implementations (CVE-2026-42510) - errata 1 Goutham Pacha Ravi (Apr 29)
