Key Flag Confusion in Sequoia-OpenPGP Library Affecting Red Hat
CVE-2026-42784
7.4HIGH
What is CVE-2026-42784?
A critical flaw exists in the Sequoia-OpenPGP library, where the inference of key flags for older certificates is inaccurately handled when a key flags subpacket is absent. This discrepancy can lead to significant security issues, as it permits an attacker to circumvent the back-signature verification process. As a result, malicious actors can falsely bind arbitrary subkeys to their own certificates, allowing them to forge signatures and severely undermine the cryptographic integrity that is essential for secure communications.