Bug 2528219 (CVE-2026-85469)

Summary: CVE-2026-85469 quay-builder-qemu: quay-builder-qemu: Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aruklets, doconnor, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-03 20:05:05 UTC
## Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope

**CWEs:** CWE-1357, CWE-494, CWE-829
**CVSS:** 8.0 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
**Component:** quay/quay-builder-qemu

### Description
The `build-and-publish` job logs in to quay.io with `secrets.QUAY_USER` / `secrets.QUAY_TOKEN` (lines 32-37) and later invokes `Noelware/docker-manifest-action@master` (line 91). Pinning a third-party Action to a branch ref means the executed code is whatever the upstream maintainer (or anyone who compromises that repo) pushes next; it is re-resolved on every run. Because `docker/login-action` has already persisted registry credentials in `~/.docker/config.json`, any code injected into the Noelware action can read and exfiltrate the Quay push token or push arbitrary images to `quay.io/projectquay/quay-builder-qemu`. The workflow also lacks a `permissions:` block, so the default GITHUB_TOKEN is available to the same step.

### Affected Locations
- `.github/workflows/build-and-publish.yaml:90-98`
- `.github/workflows/build-and-publish.yaml:32-37`

### Attack Pattern
Upstream compromise of Noelware/docker-manifest-action master branch leads to exfiltration of the quay.io push token / publication of a trojaned quay-builder-qemu image consumed by all Quay build executors.

### Remediation
Pin the third-party Action to a specific commit SHA. Add a top-level `permissions:` block restricting GITHUB_TOKEN to the minimum required scope.

---
*Source: Ex-Wing security assessment, finding FIND-001*