Package "octavia"
| Name: |
octavia
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- OpenStack Load Balancer Service - Amphora agent
- OpenStack Load Balancer as a Service - API frontend
- OpenStack Load Balancer as a Service - Common files
- OpenStack Load Balancer Service - documentation
|
| Latest version: |
1:10.1.1-0ubuntu1.5 |
| Release: |
jammy (22.04) |
| Level: |
security |
| Repository: |
universe |
Links
Other versions of "octavia" in Jammy
Packages in group
Deleted packages are displayed in grey.
Changelog
|
octavia (1:10.1.1-0ubuntu1.5) jammy-security; urgency=medium
* Fix HAProxy configuration injection vulnerabilities (LP: 2167565):
- d/p/lp2167565-1-fix-haproxy-config-injection-via-l7-redirect-
urls.patch: Reject invalid L7 policy redirect URLs (CVE-2026-94571).
- d/p/lp2167565-2-fix-haproxy-config-injection-via-tls-ciphers.patch:
Reject invalid TLS cipher strings (CVE-2026-94572).
* d/rules: Disable eventlet greendns during the package build to avoid
resolver initialization in isolated build environments.
* Fix unauthorized QoS policy deletion lock (LP: 2161500):
- d/p/lp2161500-fix-qos-policy-validation-request-context.patch:
Use the user's request context when validating QoS policies
(CVE-2026-74248).
-- Guillaume Boutry Tue, 22 Sep 2026 10:39:13 +0200
|
| CVE-2026-94571 |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f |
| CVE-2026-94572 |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The |
| CVE-2026-74248 |
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor |
|
About
-
Send Feedback to @ubuntu_updates