Can Artuc[verified]@canartucPatch
CVE‑2026‑43003 in OpenStack Ironic was patched; the vulnerability allowed malicious partition images to run binaries inside a chroot during BIOS‑boot bootloader installation, but no active exploitation or PoC is reported.
Open Source Security mailing list@oss_securityDisclosure
The post discloses a command injection flaw in OpenStack Ironic’s Python agent, noting that malicious partition images can host arbitrary binaries executed during provisioning, and links to a mailing list discussion.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE‑2026‑43003, an arbitrary code execution vulnerability affecting OpenStack Ironic‑Python‑Agent versions 1.0.0‑11.5.0.
Infoflowcloud@infoflowcloudDisclosure
A new CVE (CVE‑2026‑43003) affecting OpenStack ironic‑python‑agent 1.0.0‑11.5.0 is disclosed, noting that the agent can execute grub‑install from within a chroot; no exploit, patch, or active exploitation information is provided.
CVE@CVEnewDisclosure
The text announces a discovered vulnerability in OpenStack ironic‑python‑agent, detailing the affected versions and the specific execution flaw, but does not provide PoC, exploit, or patch information.