Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52727— lxc-ci: Pacman keyring stored in archlinux image with a private key

Quick assessment

Affected
lxc lxc-ci
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译: 包含用于 LXC 的持续集成和镜像构建脚本。在 2026-05-28 发布的 Arch Linux 镜像之前,基于 构建的镜像保留了相同的 本地签名私钥(位于 ),并将其分发到从该镜像创建的每个容器或虚拟机中。如果攻击者控制了 HTTP 软件包镜像源,或者能够拦截镜像流量,他们可以利用这个共享的 签名私钥对修改后的软件包进行签名,使受影响的客户端将其视为可信软件包。安装这些软件包将导致在客户端系统上以 root 权限执行任意代码。此问题已在 2026-05-28 或之后发布的 Arch Linux

CVSS 7.2 · High EPSS 0.33% · P26

Affected Version Matrix 1

VendorProduct Version RangeStatus
lxc lxc-ci < 2026-05-28 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52727

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
lxc-ci: Pacman keyring stored in archlinux image with a private key
Source: CVE Program / CVE List V5
Vulnerability Description
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lxc lxc-ci < 2026-05-28 -

II. Public POCs for CVE-2026-52727

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52727

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52727 (1)

Vendor Advisories for CVE-2026-52727 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-52727

No comments yet


Leave a comment