Home / mailings [USN-8814-1] Octavia vulnerabilities
Posted on 24 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8814-1
September 24, 2026
octavia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Octavia.
Software Description:
- octavia: OpenStack Load Balancer Service
Details:
It was discovered that Octavia did not properly validate TLS cipher
string fields in the Amphora provider driver. An authenticated
attacker who owns a TLS-enabled load balancer could possibly use
this issue to inject arbitrary HAProxy configuration directives.
(CVE-2026-94572)
It was discovered that Octavia did not properly validate L7 policy
redirect URL fields in the Amphora provider driver. An authenticated
attacker who owns a load balancer could possibly use this issue to
inject arbitrary HAProxy configuration directives. (CVE-2026-94571)
It was discovered that Octavia incorrectly handled quality of service
policy authorization. An authenticated attacker could possibly use
this issue to prevent deletion of another project's QoS policy.
(CVE-2026-74248)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
amphora-agent 1:18.0.0-0ubuntu2.1
octavia-driver-agent 1:18.0.0-0ubuntu2.1
octavia-health-manager 1:18.0.0-0ubuntu2.1
octavia-housekeeping 1:18.0.0-0ubuntu2.1
octavia-worker 1:18.0.0-0ubuntu2.1
python3-octavia 1:18.0.0-0ubuntu2.1
Ubuntu 24.04 LTS
amphora-agent 1:14.0.0-0ubuntu1.6
octavia-driver-agent 1:14.0.0-0ubuntu1.6
octavia-health-manager 1:14.0.0-0ubuntu1.6
octavia-housekeeping 1:14.0.0-0ubuntu1.6
octavia-worker 1:14.0.0-0ubuntu1.6
python3-octavia 1:14.0.0-0ubuntu1.6
Ubuntu 22.04 LTS
amphora-agent 1:10.1.1-0ubuntu1.5
octavia-driver-agent 1:10.1.1-0ubuntu1.5
octavia-health-manager 1:10.1.1-0ubuntu1.5
octavia-housekeeping 1:10.1.1-0ubuntu1.5
octavia-worker 1:10.1.1-0ubuntu1.5
python3-octavia 1:10.1.1-0ubuntu1.5
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8814-1
CVE-2026-74248, CVE-2026-94571, CVE-2026-94572
Package Information:
https://launchpad.net/ubuntu/+source/octavia/1:18.0.0-0ubuntu2.1
https://launchpad.net/ubuntu/+source/octavia/1:14.0.0-0ubuntu1.6
https://launchpad.net/ubuntu/+source/octavia/1:10.1.1-0ubuntu1.5
--===============2412982784414097986==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
