freenode

← digests

Knot Resolver RCE, OpenStack flaws, and kernel CVE surge

Security & Cryptography2026-07-24

Security disclosures dominated the day, led by a remote code execution fix in Knot Resolver and multiple OpenStack advisories. A bulk assignment of Linux kernel CVEs also drew debate, while PowerDNS and rpcinfo shipped patches for validation and overflow issues.

Knot Resolver DoQ heap overflow enables RCE

A heap buffer overflow in the DNS-over-QUIC listener of Knot Resolver 6.3.0 can permit remote code execution. The flaw was reported on oss-security and corrected in the 6.4.1 release. Operators exposing DoQ should upgrade to close the window for exploitation.

OpenStack Ironic agent root command execution

OpenStack issued OSSA-2026-027 for a command execution flaw in Ironic Python Agent caused by an unsanitized ntp_server configuration option, with a CVE still pending. An attacker able to supply the option can run commands as root. The issue affects bare-metal provisioning workflows that rely on the agent.

OpenStack Zaqar authentication bypass via EXTRA-SPEC

OpenStack published OSSA-2026-029 describing how an EXTRA-SPEC header lets callers bypass Keystone authentication in Zaqar, tracked under a pending CVE. Unauthenticated access to messaging resources becomes possible. Deployments that expose Zaqar should apply the available patches.

Linux kernel receives 432 CVEs in short span

The Linux kernel was assigned 432 CVEs within roughly 30 hours, prompting an oss-security thread on CVE allocation policy and practical update strategies. Eight participants examined the burden this places on maintainers and distributors. Kernel consumers may need to revisit how they triage and roll out bulk security updates.

PowerDNS Recursor DNSSEC validation bypasses

PowerDNS released Security Advisory 2026-10 for the Recursor, fixing two DNSSEC validation bypass vulnerabilities, one rated High. The updates restore correct validation behavior. Recursive resolver operators should install the patched versions to prevent forged responses.

Remotely triggerable overflows in rpcinfo

Two buffer overflows (CVE-2026-16277 and CVE-2026-16461) were disclosed in rpcinfo when it parses replies from rpcbind. Both can be triggered remotely. Systems that still ship or invoke rpcinfo should obtain fixes or restrict its use.

Ironic Python Agent credential extraction via containers

OpenStack disclosed OSSA-2026-028 (CVE-2026-54422) in which a malicious bootc container can extract credentials from Ironic Python Agent. Patches have been issued for the affected releases. Bare-metal environments that accept untrusted container images need the updates.

Bitcoin mining concentration and post-quantum migration

A short Cryptography list thread revisited Bitcoin mining concentration, noting that three pools control roughly 62 percent of hash rate, together with the practical difficulties of migrating to post-quantum signatures. Participants weighed the resulting security-model implications. The discussion remains relevant to developers watching long-term cryptocurrency resilience.