CVE-2025-44021: OSSA-2025-001 / CVE-2025-44021: OpenStack Ironic fails to strict paths used for file:// image URLs
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44021?
CVE-2025-44021 is a high-severity vulnerability that allows unintended file writing during image handling in OpenStack Ironic.
How do I fix CVE-2025-44021?
To mitigate CVE-2025-44021, upgrade OpenStack Ironic to version 29.0.1 or later.
What are the affected versions of OpenStack Ironic for CVE-2025-44021?
CVE-2025-44021 affects OpenStack Ironic versions prior to 29.0.1.
What can happen if CVE-2025-44021 is exploited?
If exploited, CVE-2025-44021 can allow a malicious project to write undesirable files to a target node's disk.
How can I determine if my system is affected by CVE-2025-44021?
You can determine if your system is affected by checking the version of OpenStack Ironic; if it's below 29.0.1, you're at risk.