Vault token leak, U-Boot overflows, NSD fixes
Security traffic on oss-security centered on a cluster-admin token leak in HashiCorp Vault Secrets Operator and integer overflows in U-Boot filesystem code. NSD also shipped a multi-CVE release while Dovecot and FreeIPMI posted lower-severity fixes.
Vault Secrets Operator leaks cluster-admin token
HashiCorp disclosed CVE-2026-8715 in Vault Secrets Operator versions 1.3.0 through 1.4.1. A tenant-writable secretIDPath can expose the operator ServiceAccount token that holds cluster-admin rights. Multi-tenant Kubernetes operators using the component face a direct path to full cluster compromise and should prioritize remediation.
Integer overflows in U-Boot filesystem parsing
Four CVEs (CVE-2025-70290 through CVE-2025-70293) were reported in U-Boot filesystem parsing. Integer overflows can lead to heap under-allocation and potential arbitrary code execution. Maintainers of embedded systems and bootloaders that parse untrusted filesystems need to evaluate exposure and apply fixes.
NSD 4.15.1 closes ACL bypass and remote DoS
NSD 4.15.1 is a security release fixing four CVEs, three rated HIGH. The issues cover ACL bypass and remote denial-of-service vectors in the authoritative DNS server. Operators running NSD should upgrade to remove these remotely reachable attack paths.
Dovecot submission-login panic
Dovecot issued Security Advisory 3/2026 for low-severity CVE-2026-33263. The flaw causes a panic in submission-login when a connection limit is reached. Mail server operators may still want the update despite the limited impact.
FreeIPMI 1.6.19 buffer overflow fixes
FreeIPMI 1.6.19 was released with fixes for potential buffer overflows and the note was forwarded to oss-security. Users of the IPMI management tools should move to the new release.