UbuntuUpdates.org

Package "octavia-housekeeping"

Name: octavia-housekeeping

Description:

OpenStack Load Balancer Service - Housekeeping manager

Latest version: 1:18.0.0-0ubuntu2.1
Release: resolute (26.04)
Level: security
Repository: universe
Head package: octavia
Homepage: https://opendev.org/openstack/octavia

Links


Download "octavia-housekeeping"


Other versions of "octavia-housekeeping" in Resolute

Repository Area Version
base universe 1:18.0.0-0ubuntu2
updates universe 1:18.0.0-0ubuntu2.1

Changelog

Version: 1:18.0.0-0ubuntu2.1 2026-09-24 14:07:38 UTC

octavia (1:18.0.0-0ubuntu2.1) resolute-security; urgency=medium

  [ Myles Penner ]
  * d/gbp.conf: Create stable/2026.1 branch.

  [ Guillaume Boutry ]
  * Fix HAProxy configuration injection vulnerabilities (LP: 2167565):
    - d/p/lp2167565-1-fix-haproxy-config-injection-via-tls-ciphers.patch:
    Reject invalid TLS cipher strings (CVE-2026-94572).
    - d/p/lp2167565-2-fix-haproxy-config-injection-via-l7-redirect-
    urls.patch: Reject invalid L7 policy redirect URLs (CVE-2026-94571).
  * Fix unauthorized QoS policy deletion lock (LP: 2161500):
    - d/p/lp2161500-fix-qos-policy-validation-request-context.patch:
      Use the user's request context when validating QoS policies
      (CVE-2026-74248).

 -- Guillaume Boutry Tue, 22 Sep 2026 10:40:45 +0200

CVE-2026-94572 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The
CVE-2026-94571 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f
CVE-2026-74248 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor



About   -   Send Feedback to @ubuntu_updates