Improper Verification of Cryptographic Signature in GnuPG - CVE-2022-34903

 

Improper Verification of Cryptographic Signature in GnuPG - CVE-2022-34903

Published: July 4, 2022 / Updated: April 4, 2025


Vulnerability identifier: #VU64909
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34903
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error in GnuPG, which allows signature spoofing via arbitrary injection into the status line. A remote attacker who controls the secret part of any signing-capable key or subkey in the victim's keyring, can take advantage of this flaw to provide a correctly-formed signature that some software, including gpgme, will accept to have validity and signer fingerprint chosen from the attacker.


Affected software

GnuPG
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
ObjectScale
IBM Cloud Pak for Watson AIOps
EMC ECS
Platform Automation Toolkit
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
NetObserv Operator
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM MQ Operator
Red Hat OpenShift distributed tracing (RHOSDT)
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
OpenShift sandboxed containers
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
gnupg2 (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnupg1
gpg2-debugsource
gpg2-debuginfo
gpg2
gpg2-lang
gnupg2
gnupg (Ubuntu package)
gnupg2 (Ubuntu package)
gpg (Ubuntu package)
gnupg2-smime
gnupg2 (Red Hat package)
gnupg2-debuginfo
gnupg2-help
gnupg2-debugsource
dirmngr-debuginfo
dirmngr
app-crypt/gnupg
Red Hat OpenShift Container Platform
IBM Security Verify Access
Voice Gateway
Cloud Pak for Security (CP4S)
Dell EMC VxRail Appliance

How to mitigate CVE-2022-34903

Install update from vendor's website.

GnuPG - update to 2.3.7
NetObserv Operator - update to 1.1.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.5, 1.1.1
OpenShift sandboxed containers - addressed in versions 1.3.1, 1.4.1
gnupg2 (Debian package) - addressed in versions 2.2.12-1+deb10u2, 2.2.27-2+deb11u2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.6, 2.4.8, 2.5.3, 2.6.2
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
Red Hat OpenShift Container Platform - addressed in versions 4.11.5, 4.11.45, 4.13.0
OpenShift Logging - addressed in versions 5.3.12, 5.3.14, 5.5.5
IBM Security Verify Access - update to 10.0.5.0
Voice Gateway - update to 1.0.8.4
ObjectScale - update to 1.4.0
gnupg1 - addressed in versions 1.4.23-15.el8, 1.4.23-18.fc35, 1.4.23-18.fc36, 1.4.23-19.el9
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
gpg2-debugsource - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2-debuginfo - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2 - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2-lang - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gnupg2 - addressed in versions 2.0.28-2.35, 2.3.7-1
gnupg (Ubuntu package) - addressed in versions 2.1.116ubuntu2.1+esm1, 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gnupg2 (Ubuntu package) - addressed in versions 2.1.116ubuntu2.1+esm1, 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gpg (Ubuntu package) - addressed in versions 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gnupg2-smime - update to 2.2.20-3
gnupg2 - update to 2.2.20-3
gnupg2 (Red Hat package) - addressed in versions 2.2.20-3.el8_6, 2.3.3-2.el9_0
gnupg2-debuginfo - update to 2.2.21-5
gnupg2-help - update to 2.2.21-5
gnupg2-debugsource - update to 2.2.21-5
gnupg2 - update to 2.2.21-5
dirmngr-debuginfo - update to 2.2.27-150300.3.5.1
dirmngr - update to 2.2.27-150300.3.5.1
gnupg2 - addressed in versions 2.3.4-2.fc35, 2.3.6-2.fc36
app-crypt/gnupg - update to 2.4.4
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.11
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7
IBM Cloud Pak for Watson AIOps - update to 3.6.1
EMC ECS - update to 3.8.0.2
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM supplied MQ Advanced container images - update to 9.3.1.0
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins