Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Ubuntu: OpenStack Keystone Critical Access Issue USN-7857-1

Ubuntu Large Esm H500
OpenStack Keystone could allow unintended access to network services.
==========================================================================
Ubuntu Security Notice USN-7857-1
November 04, 2025

keystone vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 25.04
- Ubuntu 24.04 LTS

Summary:

OpenStack Keystone could allow unintended access to network services.

Software Description:
- keystone: OpenStack identity service

Details:

Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  keystone                        2:28.0.0-0ubuntu1.1
  python3-keystone                2:28.0.0-0ubuntu1.1

Ubuntu 25.04
  keystone                        2:27.0.0-0ubuntu1.1
  python3-keystone                2:27.0.0-0ubuntu1.1

Ubuntu 24.04 LTS
  keystone                        2:25.0.0-0ubuntu1.1
  python3-keystone                2:25.0.0-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7857-1
  

Package Information:
  https://launchpad.net/ubuntu/+source/keystone/2:28.0.0-0ubuntu1.1
  
  

Ubuntu: OpenStack Keystone Critical Access Issue USN-7857-1

ubuntu
Calendar Grey November 4, 2025
Dist Ubuntu Esm H88
OpenStack Keystone vulnerability allows unauthorized access to network services. Update required for Ubuntu systems.
OpenStack Keystone could allow unintended access to network services.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS Summary: OpenStack Keystone could allow unintended access to network services. Software Description: - keystone: OpenStack identity service Details: Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access and escalate privileges.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 keystone 2:28.0.0-0ubuntu1.1 python3-keystone 2:28.0.0-0ubuntu1.1 Ubuntu 25.04 keystone 2:27.0.0-0ubuntu1.1 python3-keystone 2:27.0.0-0ubuntu1.1 Ubuntu 24.04 LTS keystone 2:25.0.0-0ubuntu1.1 python3-keystone 2:25.0.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7857-1

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7857-1

Package Information

https://launchpad.net/ubuntu/+source/keystone/2:28.0.0-0ubuntu1.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here