Bug 2437914 (CVE-2026-25793) - CVE-2026-25793 nebula: Nebula: Blocklist evasion via ECDSA Signature Malleability
Summary: CVE-2026-25793 nebula: Nebula: Blocklist evasion via ECDSA Signature Malleabi...
Keywords:
Status: NEW
Alias: CVE-2026-25793
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2438443 2438444
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-09 11:13 UTC by OSIDB Bzimport
Modified: 2026-02-10 11:36 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-09 11:13:37 UTC
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.


Note You need to log in before you can comment on or make changes to this bug.