Back

MEDIUM

rpm-ostree-client: fails to check gpg package signatures when layering

Published Jul 27, 2018

Description

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

Affected products

Remediation

Red Hat mitigation

This issue is partially mitigated on RHEL Atomic Host, where default certificate pinning ensures provenance.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 2, 2017