Description
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.
Published: 2026-09-17
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via compromised package signing
Action: Apply Patch
AI Analysis

Impact

lxc-ci builds Arch Linux container images that embed the pacman local‑signing private key into /etc/pacman.d/gnupg. An attacker who can host or alter a package mirror can use this key to sign malicious packages, which client systems built from the image accept as trusted. Installing a signed package signed with the compromised key grants the attacker root‑level code execution on the target system.

Affected Systems

The vulnerability originates in the lxc:lxc-ci repository and affects all Arch Linux images produced by that build system before the 2026‑05‑28 release. Every container or virtual machine created from those images inherits the embedded pacman signing private key and consequently is susceptible to the described attack scenario.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity vulnerability. The EPSS score of <1% suggests exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires control of an HTTP package mirror or interception of mirror traffic; the vulnerability is therefore less about a local privilege escalation and more about supply‑chain compromise via signing key theft.

Generated by OpenCVE AI on September 19, 2026 at 03:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy Arch Linux images built on or after 2026‑05‑28 that have removed the pacman local‑signing private key.
  • Rebuild and redeploy all containers or virtual machines from the updated image before releasing them to production.
  • Configure pacman to accept only trusted, externally signed packages and deny locally signed sources to prevent use of the compromised key.

Generated by OpenCVE AI on September 19, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Lxc
Lxc lxc-ci
Vendors & Products Lxc
Lxc lxc-ci

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.
Title lxc-ci: Pacman keyring stored in archlinux image with a private key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:09:46.925Z

Reserved: 2026-06-08T14:00:43.571Z

Link: CVE-2026-52727

cve-icon Vulnrichment

Updated: 2026-09-17T19:09:41.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:49.530

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-52727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key