Key Flag Confusion in Sequoia-OpenPGP Library Affecting Red Hat
CVE-2026-42784

7.4HIGH

What is CVE-2026-42784?

A critical flaw exists in the Sequoia-OpenPGP library, where the inference of key flags for older certificates is inaccurately handled when a key flags subpacket is absent. This discrepancy can lead to significant security issues, as it permits an attacker to circumvent the back-signature verification process. As a result, malicious actors can falsely bind arbitrary subkeys to their own certificates, allowing them to forge signatures and severely undermine the cryptographic integrity that is essential for secure communications.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.