Skip to content
VulniPulse
Advisory severityMedium6.5Vendor: HighRed Hat Linux

Medium [CVE-2026-54422] Credential extraction from bootc container deployment via /proc/1/root

This medium-severity Red Hat Linux advisory covers CVE-2026-54422 affecting Red Hat OpenShift Container Platform 4.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-54422 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. During bootc image deployment, the OCI registry pull secret was exposed to tenant-controlled container code running with host PID namespace visibility.

A malicious bootc container image could read the operator's registry credentials from the host filesystem via /proc/1/root, leading to credential disclosure. This could allow a project-scoped tenant to extract shared operator registry credentials, potentially affecting multiple nodes and projects.

Red Hat OpenStack Platform ships ironic-python-agent as part of its bare metal provisioning infrastructure. Deployments that use the bootc deploy_interface are affected by this vulnerability when operator-sourced registry pull secrets are used.

The bootc deployment feature was introduced in more recent versions of ironic-python-agent. Older versions of Red Hat OpenStack Platform that ship ironic-python-agent versions prior to 10.2.0 are not affected as they do not contain bootc deployment support.

Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-522.

Affected Red Hat products: Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions
  • 11.5.0

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Operators can disable the bootc deploy_interface on their Ironic conductors by setting 'disable_bootc_deploy = true' in the ironic-python-agent configuration. Additionally, operators should avoid using operator-sourced registry pull secrets (driver_info.image_pull_secret or [deploy] image_server_user/password) with the bootc deploy_interface until the fix is applied. If the bootc deploy_interface must remain enabled, restrict which users can deploy arbitrary container images by limiting access to the baremetal provisioning API.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.