Home / mailingsPDF  

[USN-8814-1] Octavia vulnerabilities

Posted on 24 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8814-1
September 24, 2026

octavia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Octavia.

Software Description:
- octavia: OpenStack Load Balancer Service

Details:

It was discovered that Octavia did not properly validate TLS cipher
string fields in the Amphora provider driver. An authenticated
attacker who owns a TLS-enabled load balancer could possibly use
this issue to inject arbitrary HAProxy configuration directives.
(CVE-2026-94572)

It was discovered that Octavia did not properly validate L7 policy
redirect URL fields in the Amphora provider driver. An authenticated
attacker who owns a load balancer could possibly use this issue to
inject arbitrary HAProxy configuration directives. (CVE-2026-94571)

It was discovered that Octavia incorrectly handled quality of service
policy authorization. An authenticated attacker could possibly use
this issue to prevent deletion of another project's QoS policy.
(CVE-2026-74248)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
amphora-agent 1:18.0.0-0ubuntu2.1
octavia-driver-agent 1:18.0.0-0ubuntu2.1
octavia-health-manager 1:18.0.0-0ubuntu2.1
octavia-housekeeping 1:18.0.0-0ubuntu2.1
octavia-worker 1:18.0.0-0ubuntu2.1
python3-octavia 1:18.0.0-0ubuntu2.1

Ubuntu 24.04 LTS
amphora-agent 1:14.0.0-0ubuntu1.6
octavia-driver-agent 1:14.0.0-0ubuntu1.6
octavia-health-manager 1:14.0.0-0ubuntu1.6
octavia-housekeeping 1:14.0.0-0ubuntu1.6
octavia-worker 1:14.0.0-0ubuntu1.6
python3-octavia 1:14.0.0-0ubuntu1.6

Ubuntu 22.04 LTS
amphora-agent 1:10.1.1-0ubuntu1.5
octavia-driver-agent 1:10.1.1-0ubuntu1.5
octavia-health-manager 1:10.1.1-0ubuntu1.5
octavia-housekeeping 1:10.1.1-0ubuntu1.5
octavia-worker 1:10.1.1-0ubuntu1.5
python3-octavia 1:10.1.1-0ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8814-1
CVE-2026-74248, CVE-2026-94571, CVE-2026-94572

Package Information:
https://launchpad.net/ubuntu/+source/octavia/1:18.0.0-0ubuntu2.1
https://launchpad.net/ubuntu/+source/octavia/1:14.0.0-0ubuntu1.6
https://launchpad.net/ubuntu/+source/octavia/1:10.1.1-0ubuntu1.5

--===============2412982784414097986==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP