UbuntuUpdates.org

Package "keystone"

Name: keystone

Description:

OpenStack identity service - Daemons

Latest version: 2:25.0.0-0ubuntu1.6
Release: noble (24.04)
Level: updates
Repository: main
Homepage: https://opendev.org/openstack/keystone

Links


Download "keystone"


Other versions of "keystone" in Noble

Repository Area Version
base main 2:25.0.0-0ubuntu1
security main 2:25.0.0-0ubuntu1.6

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:25.0.0-0ubuntu1.6 2026-09-30 17:07:19 UTC

keystone (2:25.0.0-0ubuntu1.6) noble-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via application credential token
    - debian/patches/Block-app-credential-token-rescoping.patch: Block app
      credential token rescoping Application credential tokens could be rescoped
      to system scope via token-from-token auth, bypassing the intended scope
      binding. The check only blocked project and domain scope but not system,
      allowing escalation to full system-admin privileges. . Check for any
      requested scope rather than enumerating individual scope types. in
      keystone/auth/plugins/token.py, keystone/tests/unit/test_v3_auth.py.
    - debian/patches/Ban-ec2credential-tokens-from-Keystone-API.patch: Ban
      ec2credential tokens from Keystone API in
      keystone/server/flask/request_processing/middleware/auth_context.py,
      keystone/tests/unit/test_contrib_ec2_core.py.
    - d/p/auth-encode-ec2credential-and-oauth2-credential-in-the-method-
      bitmask.patch: auth: encode ec2credential and oauth2_credential in the
      method bitmask in keystone/auth/plugins/core.py,
      keystone/tests/unit/auth/plugins/test_core.py, releasenotes/notes/reserve-
      pseudo-method-bits-404f8c553e033246.yaml.
  * debian/patches/fix-test-state-cleanup.patch: Fix test state cleanup. Dirty
      test state was causing tests to fail if they were run in a specific order
      in keystone/tests/unit/ksfixtures/backendloader.py.
  * SECURITY UPDATE: privilege escalation via delegated tokens on trust
    - debian/patches/CVE-2026-80182.patch: trusts, oauth1, app-creds: reject
      delegated tokens across all endpoints in
      keystone/api/_shared/delegation.py, keystone/api/os_oauth1.py,
      keystone/api/trusts.py, keystone/api/users.py, keystone/conf/auth.py,
      keystone/tests/unit/test_v3_application_credential.py,
      keystone/tests/unit/test_v3_oauth1.py,
      keystone/tests/unit/test_v3_trust.py,
      releasenotes/notes/bug-2153453-6f2a1d9e0c7b4a83.yaml.
    - CVE-2026-80182
  * SECURITY UPDATE: privilege escalation via delegated token reauthentication
    - debian/patches/CVE-2026-80184.patch: auth: reject delegated tokens from
      token-method reauthentication in keystone/auth/plugins/token.py,
      keystone/tests/unit/test_v3_auth.py,
      releasenotes/notes/bug-2158538-delegated-token-rescope-a1b2c3d4e5f6.yaml,
      keystone/tests/unit/test_contrib_ec2_core.py.
    - CVE-2026-80184
  * SECURITY UPDATE: unauthorized domain role assignment information exposure
    - debian/patches/CVE-2026-80183-1.patch: Prevent unauthorized project-scoped
      assignment list in keystone/common/policies/role_assignment.py,
      keystone/tests/protection/v3/test_assignment.py,
      releasenotes/notes/bug-2154645-role-assignment-tree-domain-
      bypass-f126c413bd62c375.yaml.
    - debian/patches/CVE-2026-80183-2.patch: Fix project policy allowing
      unauthorized access to root domains in
      keystone/common/policies/project.py.
    - CVE-2026-80183

 -- Isabel Garcia Contreras Mon, 28 Sep 2026 13:10:58 -0400

Source diff to previous version
CVE-2026-80182 In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new
CVE-2026-80184 In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts)
CVE-2026-80183 In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under an

Version: 2:25.0.0-0ubuntu1.4 2026-06-16 22:07:27 UTC

  keystone (2:25.0.0-0ubuntu1.4) noble-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via restricted application
    credentials
    - debian/patches/CVE-2026-33551.patch: Restrict EC2 credential creation
      when called through a restricted application credential.
    - debian/patches/CVE-2026-33551-2.patch: Add tests for restricted app
      cred guard
    - debian/patches/CVE-2026-33551-3.patch: Block restricted app creds
      from creating EC2 credentials via /credentials
    - debian/patches/CVE-2026-33551-4.patch: Block app cred tokens from
      authorizing OAuth1 requests
    - CVE-2026-33551
  * SECURITY UPDATE: authentication bypass via LDAP disabled users
    - debian/patches/CVE-2026-40683.patch: Convert LDAP user enabled attribute
      to boolean regardless of user_enabled_invert setting
    - CVE-2026-40683
  * SECURITY UPDATE: sensitive information exposure
    - d/p/cve-2026-42998-fix-user-impersonation-app-creds.patch: Fix user
      impersonation for application credentials to prevent credential
      leaks.
    - CVE-2026-42998
  * SECURITY UPDATE: RBAC policy injection in JSON requests
    - d/p/cve-2026-42999-prevent-rbac-bypass-json-query.patch: Prevent
      RBAC bypass by sanitizing JSON queries.
    - CVE-2026-42999
  * SECURITY UPDATE: Privilege escalation via impersonation and trusts
    - d/p/cve-2026-43000-forbid-trust-ops-app-creds.patch: Forbid trust
      operations with application credentials.
    - CVE-2026-43000
  * SECURITY UPDATE: EC2 credentials created with incorrect project scoping
    - d/p/cve-2026-43001-enforce-app-cred-ec2-project-boundary.patch:
      Enforce application credential EC2 project boundary.
    - CVE-2026-43001
  * SECURITY UPDATE: Federated users maintain access indefinitely
    - d/p/cve-2026-44394-preserve-expires-at-federated-rescope.patch:
      Preserve the expires_at attribute during federated token rescoping.
    - CVE-2026-44394

 -- Federico Quattrin <email address hidden> Thu, 11 Jun 2026 18:49:06 -0300

Source diff to previous version
CVE-2026-33551 An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create
CVE-2026-40683 In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert
CVE-2026-42998 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user
CVE-2026-42999 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re
CVE-2026-43000 An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi
CVE-2026-43001 An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-typ
CVE-2026-44394 An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's

Version: 2:25.0.0-0ubuntu1.2 2026-01-27 08:09:09 UTC

  keystone (2:25.0.0-0ubuntu1.2) noble; urgency=medium

  * Fix query for all users in a group while using AD nested group searches
    LP: #2112477
    - d/p/lp2112477-Fix-AD-nested-groups-issues.patch

 -- Jorge Merlino <email address hidden> Mon, 01 Dec 2025 19:37:02 -0300

Source diff to previous version

Version: 2:25.0.0-0ubuntu1.1 2025-11-05 03:07:05 UTC

  keystone (2:25.0.0-0ubuntu1.1) noble-security; urgency=medium

  * SECURITY UPDATE: Unauthenticated access to EC2/S3 token endpoints can
    grant Keystone authorization (LP: 2119646)
    - d/p/lp2119646.patch: Add a policy to enforce authentication with a
      user in the service group.
    - CVE number pending

 -- Felipe Reyes <email address hidden> Mon, 03 Nov 2025 15:17:13 +0100




About   -   Send Feedback to @ubuntu_updates