Debian dla-4800 : glance - security update

high Nessus Plugin ID 350952

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4800 advisory.

------------------------------------------------------------------------- Debian LTS Advisory DLA-4800-1 [email protected] https://www.debian.org/lts/security/ Carlos Henrique Lima Melara September 29, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : glance Version : 2:25.1.0-2+deb12u5 CVE ID : CVE-2026-71196 CVE-2026-71197 CVE-2026-71198 CVE-2026-77648 Debian Bug : 1144212 1146594

Multiple vulnerabilities were discovered in Glance, OpenStack's image storage service.

CVE-2026-71196, CVE-2026-71197 and CVE-2026-71198 / OSSA-2026-038

Three related Server-Side Request Forgery (SSRF) vulnerabilities in the web-download import method and HTTP image location APIs: insecure default URI filtering permitted an authenticated user to fetch arbitrary internal URLs, including cloud metadata endpoints; the URI validator did not perform DNS resolution before applying host filters, allowing bypass via attacker-controlled domains and DNS rebinding attacks; and when the HTTP store was enabled, the image location API lacked host filtering entirely, storing fetched content as downloadable image data, converting blind SSRF into full-read exfiltration. An unbounded fetch when the source omitted Content-Length could also fill the disk (image_size_cap is now honored).

CVE-2026-77648 / OSSN-0105

The legacy (deprecated) /v2/tasks API accepted type=import tasks which bypassed the import URI filtering (host, port and path restrictions) enforced by the modern image import, allowing an admin to fetch internal URLs from the Glance service network (SSRF). Legacy import URIs are now validated the same way as modern import.

For Debian 12 bookworm, these problems have been fixed in version 2:25.1.0-2+deb12u5.

We recommend that you upgrade your glance packages.

For the detailed security status of glance please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/glance

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Attachment:
signature.asc Description: PGP signature

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the glance packages.

See Also

https://packages.debian.org/source/bookworm/glance

https://security-tracker.debian.org/tracker/CVE-2026-71196

https://security-tracker.debian.org/tracker/CVE-2026-71197

https://security-tracker.debian.org/tracker/CVE-2026-71198

https://security-tracker.debian.org/tracker/CVE-2026-77648

https://security-tracker.debian.org/tracker/source-package/glance

Plugin Details

Severity: High

ID: 350952

File Name: debian_DLA-4800.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.22

CVSS v2

Risk Factor: Low

Base Score: 1.7

Temporal Score: 1.3

Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:N/A:N

CVSS Score Source: CVE-2026-77648

CVSS v3

Risk Factor: Low

Base Score: 2.2

Temporal Score: 2

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7

Threat Score: 3.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CVSS Score Source: CVE-2026-71198

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:glance-api, p-cpe:/a:debian:debian_linux:glance-common, p-cpe:/a:debian:debian_linux:glance-doc, p-cpe:/a:debian:debian_linux:glance, p-cpe:/a:debian:debian_linux:python3-glance

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

CVE: CVE-2026-71196, CVE-2026-71197, CVE-2026-71198, CVE-2026-77648