CVE-2026-43003: [OSSN-0100] Ironic: Command Injection in IPA (CVE-2026-43003)
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack ironic-python-agent (IPA)to a version that resolves this vulnerability.Fixed in 11.5.0Patch OSSN-0100 - Compensating control
Mitigate command injection by ensuring that deployed partition images used by IPA are trusted and not attacker-controlled, since IPA may execute grub-install inside a chroot of the deployed partition image.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43003?
CVE-2026-43003 has a high severity due to the potential for code execution with a malicious image.
How do I fix CVE-2026-43003?
To fix CVE-2026-43003, update OpenStack ironic-python-agent to a version newer than 11.5.0.
What versions are affected by CVE-2026-43003?
CVE-2026-43003 affects versions of OpenStack ironic-python-agent from 1.0.0 to 11.5.0.
What are the risks associated with CVE-2026-43003?
The risks of CVE-2026-43003 include unauthorized code execution and potential system compromise through the use of malicious images.
Is CVE-2026-43003 linked to any specific OpenStack components?
CVE-2026-43003 specifically impacts the Ironic Python Agent component of OpenStack.