Impact
lxc-ci builds Arch Linux container images that embed the pacman local‑signing private key into /etc/pacman.d/gnupg. An attacker who can host or alter a package mirror can use this key to sign malicious packages, which client systems built from the image accept as trusted. Installing a signed package signed with the compromised key grants the attacker root‑level code execution on the target system.
Affected Systems
The vulnerability originates in the lxc:lxc-ci repository and affects all Arch Linux images produced by that build system before the 2026‑05‑28 release. Every container or virtual machine created from those images inherits the embedded pacman signing private key and consequently is susceptible to the described attack scenario.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity vulnerability. The EPSS score of <1% suggests exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires control of an HTTP package mirror or interception of mirror traffic; the vulnerability is therefore less about a local privilege escalation and more about supply‑chain compromise via signing key theft.
OpenCVE Enrichment