UbuntuUpdates.org

Package "octavia-health-manager"

Name: octavia-health-manager

Description:

OpenStack Load Balancer Service - Health manager

Latest version: 1:14.0.0-0ubuntu1.6
Release: noble (24.04)
Level: security
Repository: universe
Head package: octavia
Homepage: https://opendev.org/openstack/octavia

Links


Download "octavia-health-manager"


Other versions of "octavia-health-manager" in Noble

Repository Area Version
base universe 1:14.0.0-0ubuntu1
updates universe 1:14.0.0-0ubuntu1.6

Changelog

Version: 1:14.0.0-0ubuntu1.6 2026-09-24 14:07:35 UTC

octavia (1:14.0.0-0ubuntu1.6) noble-security; urgency=medium

  * Fix HAProxy configuration injection vulnerabilities (LP: 2167565):
    - d/p/lp2167565-1-fix-haproxy-config-injection-via-l7-redirect-
    urls.patch: Reject invalid L7 policy redirect URLs (CVE-2026-94571).
    - d/p/lp2167565-2-fix-haproxy-config-injection-via-tls-ciphers.patch:
    Reject invalid TLS cipher strings (CVE-2026-94572).
  * Fix unauthorized QoS policy deletion lock (LP: 2161500):
    - d/p/lp2161500-fix-qos-policy-validation-request-context.patch:
      Use the user's request context when validating QoS policies
      (CVE-2026-74248).

 -- Guillaume Boutry Tue, 22 Sep 2026 10:39:12 +0200

CVE-2026-94571 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f
CVE-2026-94572 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The
CVE-2026-74248 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor



About   -   Send Feedback to @ubuntu_updates