[Security Advisory][designate] CVE-2026-71193 and CVE-2026-71194
Hi Yaook users, OpenStack published two CVEs for designate. One is a vulnerability in OpenStack Designate zone scheduling. An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. The other CVE is a related vulnerability in the Designate mDNS handler during triage. The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. The following images are vulnerable: * designate images before 1.0.29 * yaook release before 3.3.0 If this image is used in your cluster for the designate deployment, the cluster is vulnerable. The fixed image has been built in a private pipeline[2] which has been published alongside the advisory[1] to prove the image provenance. We recommend to add a YAOOK_OP_VERSIONS_OVERRIDE[3] variable to your Designate operator container to pull the image before the YAOOK comprehensive release is ready. |operator: extraEnv: - name: YAOOK_OP_VERSIONS_OVERRIDE value: | { "registry.yaook.cloud/yaook/designate-2024.1": "registry.yaook.cloud/yaook/designate-2024.1:1.0.29", "registry.yaook.cloud/yaook/designate-2024.2": "registry.yaook.cloud/yaook/designate-2024.2:1.0.29", "registry.yaook.cloud/yaook/designate-2025.1": "registry.yaook.cloud/yaook/designate-2025.1:1.0.29", "registry.yaook.cloud/yaook/designate-2025.2": "registry.yaook.cloud/yaook/designate-2025.2:1.0.29", "registry.yaook.cloud/yaook/designate-2026.1": "registry.yaook.cloud/yaook/designate-2026.1:1.0.29" }| More info can be found in our security advisory[1]. Regards Stefan [1] https://yaook.cloud/security-advisories-cve-2026-71193-71194/ [2] https://gitlab.com/yaook-security/images/designate/-/pipelines/2746847469 [3] https://docs.yaook.cloud/user/references/env-reference.html#envvar-YAOOK_OP_... -- Stefan Hoffmann DevOps Engineer Cloud&Heat Technologies GmbH Königsbrücker Straße 96 | 01099 Dresden +49 351 479 367 36 stefan.hoffmann@cloudandheat.com |www.cloudandheat.com Green, Open, Efficient. Ihr Cloud-Service- und Cloud-Technologie-Provider aus Dresden. https://www.cloudandheat.com/ Commercial Register: District Court Dresden Register Number: HRB 30549 VAT ID No.: DE281093504 Managing Director: Nicolas Röhrs Authorized signatory: Dr. Marius Feldmann
participants (1)
-
Stefan Hoffmann