CVE-2026-42784:
Linux Debian 취약성 분석 및 완화
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
리눅스 배포판 수정 현황
주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.
bookworm
rust-sequoia-openpgp
sid
rust-sequoia-openpgp: 2.2.0-2
trixie
rust-sequoia-openpgp
devel
rust-sequoia-openpgp
jammy
rust-sequoia-openpgp
jammy (esm-apps)
rust-sequoia-openpgp
noble
rust-sequoia-openpgp
noble (esm-apps)
rust-sequoia-openpgp
resolute
rust-sequoia-openpgp
resolute (esm-apps)
rust-sequoia-openpgp
근원: 네비디(NVD)
관련 Linux Debian 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."