Impact
An error in the sequoia-openpgp library misinterprets key flags when a key‑flags subpacket is missing. The result is that the library presents an attacker‑controlled key’s capabilities as if they were legitimate, allowing the attacker to bypass the back‑signature check. The attacker can then bind an arbitrary subkey to their own certificate and forge signatures, entirely compromising cryptographic integrity. The weakness is classified as CWE‑347, a subtle logic error in credential handling. The CVSS score of 7.4 indicates a high severity vulnerability, with potential to disrupt trust chains or invalidate data authenticity if exploited by an adversary with the ability to supply forged certificates.
Affected Systems
Red Hat products that incorporate sequoia-openpgp are affected, including Red Hat Ansible Automation Platform 2, Red Hat Confidential Compute Attestation, Red Hat Enterprise Linux 9 and 10, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Trusted Profile Analyzer and Red Hat Hardened Images. No specific version information is provided, so all current and older supported releases that include the sequoia‑openpgp library may be vulnerable.
Risk and Exploitability
The EPSS score of less than 1% suggests exploitation is currently unlikely, but the risk is non‑zero and the vulnerability is still listed in public databases. Because the flaw requires the attacker to supply a forged certificate or subkey that the target system will parse, the likely attack vector involves credential injection or malicious content delivered to a signing service. Once the back‑signature check is bypassed, an attacker could generate signatures that appear valid, leading to unauthorized data acceptance or replay attacks. The vulnerability is not yet listed in CISA KEV, indicating no publicly documented trusted exploit, yet the high CVSS score warrants vigilance.
OpenCVE Enrichment