Skip to content
VulniPulse
MediumRed Hat Linux

Medium [CVE-2026-74250] Autodetect deploy interface fails to run cleaning

This medium-severity Red Hat Linux advisory covers CVE-2026-74250 affecting Red Hat OpenShift Container Platform 4.

CVE-2026-74250 Published Aug 14, 2026Updated by vendor Aug 14, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. This can lead to operational issues where necessary cleaning procedures are not executed.

This could allow data from a previous tenant to remain on the hardware, potentially exposing sensitive information to subsequent tenants. This vulnerability was introduced in ironic version 32.0.0 and is fixed in versions 35.0.2 and 38.0.1.

Red Hat severity: Moderate. Weakness: CWE-367.

Affected Red Hat products: Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat OpenStack Platform 16.2 as not affected.

Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions
  • < 38.0.1

Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Use an explicit deploy interface (such as 'direct' or 'iscsi') instead of the 'autodetect' deploy interface. Alternatively, manually trigger cleaning on nodes after enrollment or interface changes to ensure previous tenant data is removed.

Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.