Bug 2517976 (CVE-2026-75939)

Summary: CVE-2026-75939 openshift/oc-mirror: Release signature verification: OpenPGP SignatureError checked before signed body is consumed
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, security-response-team, sghai, sidsharm, suppawar, vlaad
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-18 15:55:59 UTC
golang.org/x/crypto/openpgp.ReadMessage returns a MessageDetails whose SignatureError field is documented as valid only after UnverifiedBody has been read to EOF. In v2/internal/pkg/release/signature.go, GenerateReleaseSignatures checks md.SignatureError at line 153 before md.UnverifiedBody is consumed at line 161, so the check always observes nil. After the body is consumed and SignatureError is populated, the value is only emitted at Trace log level and never acted upon.

Net effect: any PGP message whose signature packet claims a key ID present in the release keyring (md.SignedBy != nil) is accepted even if the signature over the body is forged, reducing release-image signature verification to a key-ID match. The signed body's docker-reference is then trusted and the unverified blob is persisted to working-dir/signatures/ for replay on later runs.

An adversary able to serve responses for the signature endpoint (via TLS-terminating enterprise proxy, compromised mirror infrastructure, DNS+CA compromise, or the OCP_SIGNATURE_URL environment override) can craft a PGP message with a known Red Hat release key ID and arbitrary signature bytes, causing oc-mirror to accept and mirror a malicious release payload into a disconnected registry.

Rafael has a fix in progress but has not yet reached out to ProdSec.

Upstream: https://github.com/openshift/oc-mirror
Audited commit: 9b186403c88394b54ab491871a158a124df39a02