UbuntuUpdates.org

Package "octavia-housekeeping"

Name: octavia-housekeeping

Description:

OpenStack Load Balancer Service - Housekeeping manager

Latest version: 1:10.1.1-0ubuntu1.5
Release: jammy (22.04)
Level: security
Repository: universe
Head package: octavia
Homepage: https://github.com/openstack/octavia

Links


Download "octavia-housekeeping"


Other versions of "octavia-housekeeping" in Jammy

Repository Area Version
base universe 1:10.0.0-0ubuntu1
updates universe 1:10.1.1-0ubuntu1.5

Changelog

Version: 1:10.1.1-0ubuntu1.5 2026-09-24 14:07:31 UTC

octavia (1:10.1.1-0ubuntu1.5) jammy-security; urgency=medium

  * Fix HAProxy configuration injection vulnerabilities (LP: 2167565):
    - d/p/lp2167565-1-fix-haproxy-config-injection-via-l7-redirect-
      urls.patch: Reject invalid L7 policy redirect URLs (CVE-2026-94571).
    - d/p/lp2167565-2-fix-haproxy-config-injection-via-tls-ciphers.patch:
      Reject invalid TLS cipher strings (CVE-2026-94572).
  * d/rules: Disable eventlet greendns during the package build to avoid
    resolver initialization in isolated build environments.
  * Fix unauthorized QoS policy deletion lock (LP: 2161500):
    - d/p/lp2161500-fix-qos-policy-validation-request-context.patch:
      Use the user's request context when validating QoS policies
      (CVE-2026-74248).

 -- Guillaume Boutry Tue, 22 Sep 2026 10:39:13 +0200

CVE-2026-94571 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f
CVE-2026-94572 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The
CVE-2026-74248 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor



About   -   Send Feedback to @ubuntu_updates