CVE-2026-44919

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*

History

17 Jun 2026, 21:11

Type Values Removed Values Added
References () https://bugs.launchpad.net/ironic/+bug/2150332 - () https://bugs.launchpad.net/ironic/+bug/2150332 - Exploit, Issue Tracking, Third Party Advisory
References () https://opendev.org/openstack/ironic/commit/a3f6d735ac3642ab95b49142c7305f072ae748d0 - () https://opendev.org/openstack/ironic/commit/a3f6d735ac3642ab95b49142c7305f072ae748d0 - Patch
References () https://security.openstack.org/ossa/OSSA-2026-013.html - () https://security.openstack.org/ossa/OSSA-2026-013.html - Patch, Vendor Advisory
CPE cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
First Time Openstack
Openstack ironic

20 May 2026, 17:16

Type Values Removed Values Added
References
  • () https://security.openstack.org/ossa/OSSA-2026-013.html -

14 May 2026, 15:16

Type Values Removed Values Added
References () https://bugs.launchpad.net/ironic/+bug/2150332 - () https://bugs.launchpad.net/ironic/+bug/2150332 -

14 May 2026, 02:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 02:17

Updated : 2026-06-17 21:11


NVD link : CVE-2026-44919

Mitre link : CVE-2026-44919

CVE.ORG link : CVE-2026-44919


JSON object : View

Products Affected

openstack

  • ironic
CWE
CWE-696

Incorrect Behavior Order