SB20260425220 - Anolis OS update for cosign
Published: April 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-2026-22703)
The vulnerability allows a local user to cause acceptance of an invalid signing bundle.
The vulnerability exists due to insufficient verification of data authenticity in Rekor entry verification when verifying a crafted Cosign bundle. A local user can include an arbitrary valid Rekor entry in the bundle to cause acceptance of an invalid signing bundle.
This only affects verification when a trusted root is provided via --trusted-root or fetched automatically from a TUF repository and no trusted key material is provided via SIGSTORE_REKOR_PUBLIC_KEY.
Remediation
Install update from vendor's website.