PT-2026-105037 · Azure Linux · Kata-Containers-Cc
Published
2026-09-16
·
Updated
2026-09-16
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kata-Containers-Cc