Executive brief
OpenStack Ironic, a service for managing bare metal infrastructure, is vulnerable to a security flaw that allows an attacker to overwrite files on the host system. By providing a specially crafted ISO image during the server deployment process, an authorized user can bypass security restrictions to modify sensitive system files. This could lead to a compromise of the management server or the target hardware being deployed.
Technical details
A path traversal vulnerability exists in OpenStack Ironic's ISO handling code, specifically within the `_extract_iso()` function in `images.py`. The component uses `os.path.join()` to combine extraction directories with paths retrieved from an ISO image via `pycdlib` without proper validation or normalization of `../` sequences. An authenticated attacker with permissions to deploy nodes using virtual media, configdrive, or the anaconda interface can provide a malicious ISO containing traversal sequences. This allows the attacker to overwrite arbitrary files as the `ironic-conductor` user on the conductor host or on the target disk during deployment. The vulnerability is mitigated by the requirement for high privileges and the complexity of crafting an ISO that adheres to specific filesystem constraints (like the 8.3 filename schema in some contexts).
Affected products
- OpenStack Ironic >= 17.0.0, < 26.1.7; >= 27.0.0, < 29.0.6; >= 30.0.0, < 32.0.2; >= 33.0.0, < 35.0.2
Timeline
- 2026-04-14: disclosed: Bug reported to Launchpad by Dmitry Tantsur
- 2026-06-03: advisory: OpenStack Security Advisory OSSA-2026-018 issued
- 2026-06-04: patched: Initial publication of CVE and GitHub advisory