Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-42784
Linux Debian vulnerability analysis and mitigation

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rust-sequoia-openpgp

Affected

sid

rust-sequoia-openpgp: 2.2.0-2

Fixed

trixie

rust-sequoia-openpgp

Affected

Ubuntu

Unknown

devel

rust-sequoia-openpgp

Unknown

jammy

rust-sequoia-openpgp

Unknown

jammy (esm-apps)

rust-sequoia-openpgp

Unknown

noble

rust-sequoia-openpgp

Unknown

noble (esm-apps)

rust-sequoia-openpgp

Unknown

resolute

rust-sequoia-openpgp

Unknown

resolute (esm-apps)

rust-sequoia-openpgp

Unknown

RHEL / CentOS

Affected

OpenShift

kata-containers.src

Affected

RHEL 9

rust-rpm-sequoia.src

Affected

RHEL 10

rust-rpm-sequoia.src

Affected

SourceNVD

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86320HIGH7.8
  • Linux Debian logoLinux Debian
  • flatpak-builder
NoYesSep 17, 2026
CVE-2026-91841HIGH7.8
  • Linux Debian logoLinux Debian
  • network-manager-vpnc
NoNoSep 17, 2026
CVE-2026-91840HIGH7.8
  • Linux Debian logoLinux Debian
  • network-manager-vpnc
NoNoSep 17, 2026
CVE-2026-91839HIGH7.8
  • Linux Debian logoLinux Debian
  • network-manager-fortisslvpn
NoNoSep 17, 2026
CVE-2026-91838HIGH7.8
  • Linux Debian logoLinux Debian
  • network-manager-sstp
NoNoSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management