Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-42784— Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion

Quick assessment

Affected
Red Hat Confidential Compute Attestation
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 sequoia-openpgp 库中发现了一个漏洞。当旧版证书中缺少密钥标志子包(key flags subpacket)时,该库会错误地推断密钥标志,导致对密钥能力的理解出现偏差。这种密钥标志的混淆使得攻击者能够绕过回签(back-signature)检查。因此,攻击者可以非法地将任意子密钥绑定到自己的证书上,并伪造签名,从而彻底破坏密码学完整性。

CVSS 7.4 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-42784

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Trusted Profile Analyzer - cpe:/a:redhat:trusted_profile_analyzer:2
Red Hat Red Hat Trusted Profile Analyzer - cpe:/a:redhat:trusted_profile_analyzer:3

II. Public POCs for CVE-2026-42784

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-42784

登录查看更多情报信息。

Other References for CVE-2026-42784 (1)

Same Patch Batch · Red Hat · 2026-09-16 · 9 CVEs total

CVE-2026-74909 8.1 HIGH Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo
CVE-2026-79651 7.5 HIGH Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
CVE-2026-18212 7.5 HIGH Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state
CVE-2026-17526 7.2 HIGH Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t
CVE-2026-92615 6.6 MEDIUM Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena
CVE-2026-92358 6.4 MEDIUM Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil
CVE-2026-92091 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops
CVE-2026-19607 5.3 MEDIUM Keycloak-services: keycloak-services: broker-originated username collision causes account

IV. Related Vulnerabilities

V. Comments for CVE-2026-42784

No comments yet


Leave a comment