Improper Verification of Cryptographic Signature in GnuPG - CVE-2022-34903
Published: July 4, 2022 / Updated: April 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error in GnuPG, which allows signature spoofing via arbitrary injection into the status line. A remote attacker who controls the secret part of any signing-capable key or subkey in the victim's keyring, can take advantage of this flaw to provide a correctly-formed signature that some software, including gpgme, will accept to have validity and signer fingerprint chosen from the attacker.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
ObjectScale
IBM Cloud Pak for Watson AIOps
EMC ECS
Platform Automation Toolkit
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
NetObserv Operator
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM MQ Operator
Red Hat OpenShift distributed tracing (RHOSDT)
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
OpenShift sandboxed containers
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
gnupg2 (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnupg1
gpg2-debugsource
gpg2-debuginfo
gpg2
gpg2-lang
gnupg2
gnupg (Ubuntu package)
gnupg2 (Ubuntu package)
gpg (Ubuntu package)
gnupg2-smime
gnupg2 (Red Hat package)
gnupg2-debuginfo
gnupg2-help
gnupg2-debugsource
dirmngr-debuginfo
dirmngr
app-crypt/gnupg
Red Hat OpenShift Container Platform
IBM Security Verify Access
Voice Gateway
Cloud Pak for Security (CP4S)
Dell EMC VxRail Appliance
How to mitigate CVE-2022-34903
NetObserv Operator - update to 1.1.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.5, 1.1.1
OpenShift sandboxed containers - addressed in versions 1.3.1, 1.4.1
gnupg2 (Debian package) - addressed in versions 2.2.12-1+deb10u2, 2.2.27-2+deb11u2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.6, 2.4.8, 2.5.3, 2.6.2
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
Red Hat OpenShift Container Platform - addressed in versions 4.11.5, 4.11.45, 4.13.0
OpenShift Logging - addressed in versions 5.3.12, 5.3.14, 5.5.5
IBM Security Verify Access - update to 10.0.5.0
Voice Gateway - update to 1.0.8.4
ObjectScale - update to 1.4.0
gnupg1 - addressed in versions 1.4.23-15.el8, 1.4.23-18.fc35, 1.4.23-18.fc36, 1.4.23-19.el9
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
gpg2-debugsource - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2-debuginfo - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2 - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gpg2-lang - addressed in versions 2.0.24-9.11.1, 2.2.5-150000.4.22.1, 2.2.27-150300.3.5.1
gnupg2 - addressed in versions 2.0.28-2.35, 2.3.7-1
gnupg (Ubuntu package) - addressed in versions 2.1.116ubuntu2.1+esm1, 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gnupg2 (Ubuntu package) - addressed in versions 2.1.116ubuntu2.1+esm1, 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gpg (Ubuntu package) - addressed in versions 2.2.4-1ubuntu1.6, 2.2.19-3ubuntu2.2, 2.2.20-1ubuntu4.1, 2.2.27-3ubuntu2.1
gnupg2-smime - update to 2.2.20-3
gnupg2 - update to 2.2.20-3
gnupg2 (Red Hat package) - addressed in versions 2.2.20-3.el8_6, 2.3.3-2.el9_0
gnupg2-debuginfo - update to 2.2.21-5
gnupg2-help - update to 2.2.21-5
gnupg2-debugsource - update to 2.2.21-5
gnupg2 - update to 2.2.21-5
dirmngr-debuginfo - update to 2.2.27-150300.3.5.1
dirmngr - update to 2.2.27-150300.3.5.1
gnupg2 - addressed in versions 2.3.4-2.fc35, 2.3.6-2.fc36
app-crypt/gnupg - update to 2.4.4
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.11
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7
IBM Cloud Pak for Watson AIOps - update to 3.6.1
EMC ECS - update to 3.8.0.2
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM supplied MQ Advanced container images - update to 9.3.1.0
Robotic Process Automation for Cloud Pak - update to 21.0.6
External References
Related Security Bulletins
- Signature spoofing attack in GnuPG
- Debian update for gnupg2
- Ubuntu update for gnupg2
- Slackware Linux update for gnupg2
- Ubuntu update for gnupg
- SUSE update for gpg2
- SUSE update for gpg2
- Amazon Linux AMI update for gnupg2
- SUSE update for gpg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Red Hat Enterprise Linux 9 update for gnupg2
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Logging 5.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.5
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT)
- Multiple vulnerabilities in OpenShift sandboxed containers
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in NetObserv Operator
- Improper verification of cryptographic signature in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Dell ECS
- VMware Tanzu products update for GnuPG
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- openEuler update for gnupg2
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for gnupg2
- Multiple vulnerabilities in Dell ObjectScale
- Gentoo update for GnuPG
- Fedora 36 update for gnupg2
- Fedora 35 update for gnupg2
- Fedora 36 update for gnupg1
- Fedora 35 update for gnupg1
- Fedora EPEL 9 update for gnupg1
- Fedora EPEL 8 update for gnupg1
- Anolis OS update for gnupg2