Bug 2517976 (CVE-2026-75939) - CVE-2026-75939 openshift/oc-mirror: Release signature verification: OpenPGP SignatureError checked before signed body is consumed
Summary: CVE-2026-75939 openshift/oc-mirror: Release signature verification: OpenPGP S...
Keywords:
Status: NEW
Alias: CVE-2026-75939
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-18 15:55 UTC by OSIDB Bzimport
Modified: 2026-09-21 13:45 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-18 15:55:59 UTC
golang.org/x/crypto/openpgp.ReadMessage returns a MessageDetails whose SignatureError field is documented as valid only after UnverifiedBody has been read to EOF. In v2/internal/pkg/release/signature.go, GenerateReleaseSignatures checks md.SignatureError at line 153 before md.UnverifiedBody is consumed at line 161, so the check always observes nil. After the body is consumed and SignatureError is populated, the value is only emitted at Trace log level and never acted upon.

Net effect: any PGP message whose signature packet claims a key ID present in the release keyring (md.SignedBy != nil) is accepted even if the signature over the body is forged, reducing release-image signature verification to a key-ID match. The signed body's docker-reference is then trusted and the unverified blob is persisted to working-dir/signatures/ for replay on later runs.

An adversary able to serve responses for the signature endpoint (via TLS-terminating enterprise proxy, compromised mirror infrastructure, DNS+CA compromise, or the OCP_SIGNATURE_URL environment override) can craft a PGP message with a known Red Hat release key ID and arbitrary signature bytes, causing oc-mirror to accept and mirror a malicious release payload into a disconnected registry.

Rafael has a fix in progress but has not yet reached out to ProdSec.

Upstream: https://github.com/openshift/oc-mirror
Audited commit: 9b186403c88394b54ab491871a158a124df39a02


Note You need to log in before you can comment on or make changes to this bug.