GnuPG: interaction between the sks-keyserver code and GnuPG allows for a Certificate Spamming Attack which leads to persistent DoS
Published Jun 29, 2019
7.5
HIGHCVSS 3.1
EPSS 2.52%
Description
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
Affected products
No data.
Configuration 1
- ≤ 2.2.16
- ≤ 1.2.0
Configuration 2
- 29
- 30
Configuration 4
- ≥ 5.0.0 · ≤ 5.1.0
No data.
Red Hat Enterprise Linux 8
gnupg2-0:2.2.20-2.el8
Fixed · RHSA-2020:4490
Red Hat Enterprise Linux 5
gnupg
Out of support scope
Red Hat Enterprise Linux 5
gnupg2
Out of support scope
Red Hat Enterprise Linux 6
gnupg2
Out of support scope
Red Hat Enterprise Linux 7
gnupg2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | gnupg2-0:2.2.20-2.el8 | Fixed | RHSA-2020:4490 |
| Red Hat Enterprise Linux 5 | gnupg | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | gnupg2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | gnupg2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gnupg2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is a certificate spamming attack, against key servers which use the sks-keyserver software. Attackers were able to poison some certificates in the SKS keyserver network. When GnuPG users import these certificate their installations will break. Currently there is no patch available for GnuPG. Users are encouraged to apply the mitigation mentioned on this page. Lastly there is no way to currently detect which certificates have been poisoned. Users of GnuPG who import only locally created certificates or those created within their infrastructure and later use them for verification etc are not affected by this flaw.
Red Hat mitigation
As per upstream: High-risk users should stop using the keyserver network immediately. 1. Open ~/.gnupg/gpg.conf in a text editor. Ensure there is no line starting with keyserver. If there is, remove it. 2. Open ~/.gnupg/dirmngr.conf in a text editor. Add the line "keyserver hkps://keys.openpgp.org" to the end of it. keys.openpgp.org is a new experimental keyserver which is not part of the keyserver network and has some features which make it resistant to this attack. It is not a drop-in replacement: it has some limitations (for instance, its search functionality is sharply constrained). However, once you make this change you will be able to run gpg --refresh-keys with confidence. For installations which are currently rendered unusable by this attack, the following repair method is advised: 1. If you know which certificate is likely poisoned, try deleting it. Once the installation becomes usable again, you can acquire a new unpoisoned copy of the certificate and re-import it. 2. If you do not know which certificate is poisoned, best option is to get a list of all your certificate IDs, delete your keyrings completely, and rebuild from scratch using known-good copies of the public certificates.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (17 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 2.52% (0.02524) | 84.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.66% (0.02663) | 83.69th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.74% (0.00738) | 72.08th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.10% (0.02099) | 82.66th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.74% (0.00738) | 71.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.93% (0.00933) | 83.70th | v3 (v2023.03.01) |
| Jun 22, 2024 | 1.02% (0.01019) | 83.84th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.04% (0.01042) | 82.25th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.58% (0.00577) | 75.26th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.53% (0.00527) | 73.39th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.29% (0.23285) | 94.69th | v2 (v2022.01.01) |
| Feb 3, 2022 | 12.44% (0.12435) | 88.79th | v1 |
| Jan 6, 2022 | 12.44% (0.12435) | 88.65th | v1 |
| Jan 5, 2022 | 3.07% (0.03068) | 81.66th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.57% (0.02567) | 0.00th | v1 |
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00039.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/articles/4264021
- https://access.redhat.com/security/cve/CVE-2019-13050 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1726146 Issue Tracking
- https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f x_refsource_MISCExploitIssue TrackingMitigationThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUK2YRO6QIH64WP2LRA5D4LACTXQPPU4/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CP4ON34YEXEZDZOXXWV43KVGGO6WZLJ5/ vendor-advisoryx_refsource_FEDORA
- https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-13050
- https://support.f5.com/csp/article/K08654551 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K08654551?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://twitter.com/lambdafu/status/1147162583969009664 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-13050
Change history (0)
No recorded changes yet.