CVE-2026-43003
Summary
| CVE | CVE-2026-43003 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-01 09:16:17 UTC |
| Updated | 2026-09-09 13:20:05 UTC |
| Description | An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.009830000 probability, percentile 0.602200000 (date 2026-09-09)
Problem Types: CWE-829 | CWE-78 | CWE-829 CWE-829 Inclusion of Functionality from Untrusted Control Sphere | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | CVSS | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 8 | HIGH | CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8 | HIGH | CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Ironic Python Agent | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OpenStack | Ironic-python-agent | affected 10.2.3 semver | Not specified |
| CNA | OpenStack | Ironic-python-agent | affected 11.0.0 11.2.1 semver | Not specified |
| CNA | OpenStack | Ironic-python-agent | affected 11.3.0 11.5.1 semver | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4.19 | unaffected 1787545085 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4.20 | unaffected 1787735456 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4.21 | unaffected 1786942282 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4.22 | unaffected 1785883346 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/security/cve/CVE-2026-43003 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| www.openwall.com/lists/oss-security/2026/06/16/11 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| access.redhat.com/errata/RHSA-2026:60454 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:51038 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugs.launchpad.net/ironic-python-agent/+bug/2148310 | [email protected] | bugs.launchpad.net | Issue Tracking |
| access.redhat.com/errata/RHSA-2026:60446 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43003.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| github.com/openstack/ironic-python-agent/blob/236b33abffe6688afc39c21e35... | [email protected] | github.com | Product |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:57801 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-05-01T09:00:58.874Z | Reported to Red Hat. |
| ADP | 2026-05-01T00:00:00.000Z | Made public. |
Solutions
ADP: RHSA-2026:60454: Red Hat OpenShift Container Platform 4.19
ADP: RHSA-2026:60446: Red Hat OpenShift Container Platform 4.20
ADP: RHSA-2026:57801: Red Hat OpenShift Container Platform 4.21
ADP: RHSA-2026:51038: Red Hat OpenShift Container Platform 4.22
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.