-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 Aug 2026 09:41:35 +0200 Source: keystone Architecture: source Version: 2:27.0.0-3+deb13u5 Distribution: trixie-security Urgency: medium Maintainer: Debian OpenStack Changed-By: Thomas Goirand Closes: 1145669 1145816 Changes: keystone (2:27.0.0-3+deb13u5) trixie-security; urgency=medium . * CVE-2026-80184: Delegation bypass in trust, OAuth1, and application credential operations. * CVE-2026-80182: Tokens obtained via application credential or EC2 credential authentication can escape their intended project scope through token-method reauthentication. An application-credential token scoped to one project can be exchanged via POST /v3/auth/tokens with no explicit scope, causing Keystone to issue a new token scoped to the owner's default project. For EC2-derived tokens the bypass is broader: because they carry no delegation markers, they can rescope to any project where the underlying user has role assignments. * Add new patches (Closes: #1145669): - CVE-2026-80182_CVE-2026-80184_1_Block_app_credential_token_resco....patch - CVE-2026-80182_CVE-2026-80184_2_auth_encode_ec2credential_and_oa....patch - CVE-2026-80182_CVE-2026-80184_3_trusts_oauth1_app-creds_reject_d....patch - CVE-2026-80182_CVE-2026-80184_4_auth_reject_delegated_tokens_fro....patch * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch Checksums-Sha1: 8b7fa7356687caf2018cc031b84437f216098b6f 3486 keystone_27.0.0-3+deb13u5.dsc 896a6f57c727fa62d0aec10d5c8844b40cc42bdb 1098444 keystone_27.0.0.orig.tar.xz 590937c413889aa118ec5e2dfa3d39a54af4ced6 81732 keystone_27.0.0-3+deb13u5.debian.tar.xz d0acf734afd9fa9f74da92a47f411fd59c9bae47 18779 keystone_27.0.0-3+deb13u5_amd64.buildinfo Checksums-Sha256: 597252e68249fbbe1266d0778c459408508b432f4e4d9bb33f33c3ac690c81a7 3486 keystone_27.0.0-3+deb13u5.dsc 223b27dc676dabd6c9d67e4409fe086f92b5d47bf71ee8c724c3e0d13f26d635 1098444 keystone_27.0.0.orig.tar.xz b80c4e12d419b1cd19b7fbf31fc615854bf8dee95001bb59fa5c4e9a189b2656 81732 keystone_27.0.0-3+deb13u5.debian.tar.xz 3f48302bfafa73455f8cc84e85ca1120fc8a90a79d1f7e3cc23d48ece90aea89 18779 keystone_27.0.0-3+deb13u5_amd64.buildinfo Files: df7fd282803d1e8db8bed179433a4772 3486 net optional keystone_27.0.0-3+deb13u5.dsc d8119041a4ba1c4545ab5dabe9ae65b9 1098444 net optional keystone_27.0.0.orig.tar.xz abaf99efbe87784c9ab911f75ccb2e42 81732 net optional keystone_27.0.0-3+deb13u5.debian.tar.xz e83a67b6056bcc9fa8be77219176f2cc 18779 net optional keystone_27.0.0-3+deb13u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqVMGAACgkQ1BatFaxr Q/5Lfw//ekgssRChl7JfyUUhn5+CnrmSfYuGlYu+Yrl0KtSGo89HmXaS3Lq0u/Nx ild5Ulxdj6A23HsW8s3huMafD+a93sUWogLDEDLPWwRo6gXtNo00kpr//DaOir2N lcEU/ryPdTusHSTJfuhEGjF6g1BuBVz8KDrd8M3gfgosilqXG676Vo6BfIAsn5OP bo8lt9xQRHC72dtgZkQB7C7ZzLFuyG8gm8+FO6wwqg+NCkLHe3RwVZ+9MawBi0tA 65lb8Atf/UXVrjfM/3dO7mYdKzxPsDHNHnUjdq7Q2dnupx4/WoRc6Vx2ZxJB5ZTC 3pn84FZx5bB7O2b1Ka0F2DmDmyqoIuFKSWDfpgls5mvS1GfG+YAeZrG1g1/H/7s7 Xv+xbRM1RV4wjMj61Hhbdt/fErsvHrJVa2u7vtYjc1o59F4+oL4NAg8zbiGdJ4Rf W9iCNyS9tHlxnPbe/IvTAKDYQrIYY7J7s+ZBvUKkWzdz6gO37ihHJteIXIrSTCX6 aTrVFrSvm1o4kBPltClgslrgPm+1TxWn1J1b0QJyWyI3b+hDwBlN/SDo0vTk68hR E9ZDXkqZ/4/hmx0BhAEwM9aut2BCZvejVVif8u8Ww1dOe5ItS9B0zmCjgfMV3Axl iQ/R3gH+74ySnLu27hSX2TZkVqbYFSmjNdgUHvwh0w3c/v1zSco= =Z+0F -----END PGP SIGNATURE-----