MEDIUM5.5
PYSEC-2026-3079
OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions
Quick fix
PYSEC-2026-3079 — sushy-tools: upgrade to the fixed version with the command below.
pip install --upgrade 'sushy-tools>=0.21.1'Details
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-44020[ADVISORY]
- https://github.com/umago/virtualbmc[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GAD7QJIUWPCKJIGYP7PPHH5DILOEONFE[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEQVJF3OQGSDCSQTQQSC54JEGLMSNB4Q[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMSUGS4B6EBRHBJMTRXL5RIKJTZTEMJC[WEB]
- https://review.opendev.org/c/openstack/sushy-tools/+/862625[WEB]
- https://review.opendev.org/c/openstack/virtualbmc/+/862620[WEB]
- https://storyboard.openstack.org/#!/story/2010382[WEB]
- https://pypi.org/project/sushy-tools[PACKAGE]
- https://github.com/advisories/GHSA-5pj3-6fqm-8m7m[ADVISORY]