← All Advisories

CVE-2026-42784

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-42784

Key Details

CVECVE-2026-42784
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is none; integrity impact is high; availability impact is none.
Affected productssee table below
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Hardened Images
Red HatRed Hat OpenShift Container Platform 4
Red HatConfidential Compute Attestation
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Satellite 6
Red HatRed Hat Trusted Profile Analyzer
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42784
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-42784