Package "octavia-api"
| Name: |
octavia-api
|
Description: |
OpenStack Load Balancer as a Service - API frontend
|
| Latest version: |
1:18.0.0-0ubuntu2.1 |
| Release: |
resolute (26.04) |
| Level: |
updates |
| Repository: |
universe |
| Head package: |
octavia |
| Homepage: |
https://opendev.org/openstack/octavia |
Links
Download "octavia-api"
Other versions of "octavia-api" in Resolute
Changelog
|
octavia (1:18.0.0-0ubuntu2.1) resolute-security; urgency=medium
[ Myles Penner ]
* d/gbp.conf: Create stable/2026.1 branch.
[ Guillaume Boutry ]
* Fix HAProxy configuration injection vulnerabilities (LP: 2167565):
- d/p/lp2167565-1-fix-haproxy-config-injection-via-tls-ciphers.patch:
Reject invalid TLS cipher strings (CVE-2026-94572).
- d/p/lp2167565-2-fix-haproxy-config-injection-via-l7-redirect-
urls.patch: Reject invalid L7 policy redirect URLs (CVE-2026-94571).
* Fix unauthorized QoS policy deletion lock (LP: 2161500):
- d/p/lp2161500-fix-qos-policy-validation-request-context.patch:
Use the user's request context when validating QoS policies
(CVE-2026-74248).
-- Guillaume Boutry Tue, 22 Sep 2026 10:40:45 +0200
|
| CVE-2026-94572 |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The |
| CVE-2026-94571 |
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix f |
| CVE-2026-74248 |
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphor |
|
About
-
Send Feedback to @ubuntu_updates