-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 Aug 2026 09:41:35 +0200 Source: keystone Binary: keystone keystone-doc python3-keystone Architecture: all Version: 2:27.0.0-3+deb13u5 Distribution: trixie-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Thomas Goirand Description: keystone - OpenStack identity service keystone-doc - OpenStack identity service - documentation python3-keystone - OpenStack identity service - library Closes: 1145669 1145816 Changes: keystone (2:27.0.0-3+deb13u5) trixie-security; urgency=medium . * CVE-2026-80184: Delegation bypass in trust, OAuth1, and application credential operations. * CVE-2026-80182: Tokens obtained via application credential or EC2 credential authentication can escape their intended project scope through token-method reauthentication. An application-credential token scoped to one project can be exchanged via POST /v3/auth/tokens with no explicit scope, causing Keystone to issue a new token scoped to the owner's default project. For EC2-derived tokens the bypass is broader: because they carry no delegation markers, they can rescope to any project where the underlying user has role assignments. * Add new patches (Closes: #1145669): - CVE-2026-80182_CVE-2026-80184_1_Block_app_credential_token_resco....patch - CVE-2026-80182_CVE-2026-80184_2_auth_encode_ec2credential_and_oa....patch - CVE-2026-80182_CVE-2026-80184_3_trusts_oauth1_app-creds_reject_d....patch - CVE-2026-80182_CVE-2026-80184_4_auth_reject_delegated_tokens_fro....patch * CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree. Applied upstream patch (Closes: #1145816): - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch Checksums-Sha1: 94ce885a00f07c6b8690d50d7b7b9d4b7ca74c39 2261336 keystone-doc_27.0.0-3+deb13u5_all.deb c48b755e2f6c2bf7cf673a8efeebe01d86aca41f 18589 keystone_27.0.0-3+deb13u5_all-buildd.buildinfo e507e1c4ee1b577266df600308b8744d48b88905 75480 keystone_27.0.0-3+deb13u5_all.deb 0bc88b887a5a772be88d68b03c036987b88aa2a1 743780 python3-keystone_27.0.0-3+deb13u5_all.deb Checksums-Sha256: bb152e77615078e561ae1d7912a81b60a10e879bd18caa44abcfac90502e2f6b 2261336 keystone-doc_27.0.0-3+deb13u5_all.deb da35e673cd4ed285c5878e794c79d742de43dccc2b2cf281950425f06bacccf8 18589 keystone_27.0.0-3+deb13u5_all-buildd.buildinfo 7cab0307c39f5652e3a0112b1d42cc492f1bb4c643dd78eeb54d2665bd80466b 75480 keystone_27.0.0-3+deb13u5_all.deb 0ef71eb639fb7c9e3ecde3a0457c4f31ac8e4c859eca59db8fba223054c12b53 743780 python3-keystone_27.0.0-3+deb13u5_all.deb Files: 96c2350f7d0d5e549cfd08f6be60a8ef 2261336 doc optional keystone-doc_27.0.0-3+deb13u5_all.deb b70b62408a8e47778d0f05c3a0de070c 18589 net optional keystone_27.0.0-3+deb13u5_all-buildd.buildinfo 3d1d4d336fd3e9f3a476e3c7515fad2c 75480 net optional keystone_27.0.0-3+deb13u5_all.deb 1b14929a13807ce5284b2571f1572995 743780 python optional python3-keystone_27.0.0-3+deb13u5_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXLxUpUHQBQBTDtd4aBVi67oXtfkFAmqVOJwACgkQaBVi67oX tfmO4RAAqq06c9W8mvBZoUcTbmmwQdZyKmJG7LXL2hUp5en+I8YcfBMGK5n2keGe zDAWvG1IvH+QJga7dekpk17uuD9qWnG56OFAJw46zuzuVj2VWrTo+mPLIapY/AE8 Dx77Ka1eXDwVUPa+ee3/yI3D2VWOE6M4eR/BY+ARhlqDv9DTdYUfkCAgqua7wmLi t7j5IeIrUhZ4rVIuiU1Qpdg8vLUIH4bFWKfS5Spj1eRAqWLdtPV9xg87dAOwXZq1 nGc/FeGQrMnAa3F3ZSs7k/N2SdnxafXJ1DNMvj/bjBZRUj3wc2KZqAcDFYskoIny Z70r6iu1ClqXpcvJ7omN5mi0gXGRRhfvXlehFbhi9p1fT1W5u1yYLfAX18z4IUua mL5mJeiV4dQd8odIONPfKXCuNqRQ2mjCAehdUadGo5je8Q3Ozlg21Rq9reJl0Fkl CdO1zHT69fFPehxkyxxaxfyOsQroF7SZq615W4CTlpFUATKqglctIy2sGSN/SgOj vALUYQZ7QbRQOmNCygzeFX5KyQMIbdH2CJx/pvKO0uHATYhWidfhGFEVTgCgyzX9 TmmDD9g0ZysDQ1k45HrYI/2yx89f3lEYRYIAzpOUzw5C98cZavRpRViakVB99YKK Cm4VdSJHWixSsWXw8X5IsrGpAcNb8rX4jd9Z5Vs7YXAPNnApFzQ= =PBcH -----END PGP SIGNATURE-----