A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-appstream-dataalma-upgrade-libxmlb | May 4, 2022 | Sep 15, 2020 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Sep 15, 2020 | |
| Centos_linux | — | centos-upgrade-appstream-datacentos-upgrade-fwupdcentos-upgrade-fwupd-debuginfocentos-upgrade-fwupd-debugsourcecentos-upgrade-gnome-softwarecentos-upgrade-gnome-software-debuginfocentos-upgrade-gnome-software-debugsourcecentos-upgrade-libxmlbcentos-upgrade-libxmlb-debuginfocentos-upgrade-libxmlb-debugsourcecentos-upgrade-libxmlb-tests-debuginfo | Nov 5, 2020 | Sep 15, 2020 |
| Debian | debian-upgrade-fwupddebian-upgrade-libjcat | Jul 10, 2020 | Jul 10, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-libjcatgentoo-linux-upgrade-sys-apps-fwupd | Jul 28, 2020 | Jul 26, 2020 | |
| Oracle_linux | — | oracle-linux-upgrade-appstream-dataoracle-linux-upgrade-fwupdoracle-linux-upgrade-gnome-softwareoracle-linux-upgrade-libxmlb | Nov 12, 2020 | Jun 5, 2020 |
| Redhat_linux | redhat-upgrade-appstream-dataredhat-upgrade-fwupdredhat-upgrade-fwupd-debuginforedhat-upgrade-fwupd-debugsourceredhat-upgrade-gnome-softwareredhat-upgrade-gnome-software-debuginforedhat-upgrade-gnome-software-debugsourceredhat-upgrade-libxmlbredhat-upgrade-libxmlb-debuginforedhat-upgrade-libxmlb-debugsourceredhat-upgrade-libxmlb-tests-debuginfo | Nov 5, 2020 | Sep 15, 2020 | |
| Rocky_linux | rocky-upgrade-libxmlbrocky-upgrade-libxmlb-debuginforocky-upgrade-libxmlb-debugsource | Mar 12, 2024 | Sep 15, 2020 | |
| Suse | — | suse-upgrade-dfu-toolsuse-upgrade-fwupdsuse-upgrade-fwupd-develsuse-upgrade-fwupd-langsuse-upgrade-fwupdtpmevlogsuse-upgrade-jcat-toolsuse-upgrade-libfwupd2suse-upgrade-libfwupdplugin1suse-upgrade-libjcat-develsuse-upgrade-libjcat1suse-upgrade-typelib-1_0-fwupd-2_0suse-upgrade-typelib-1_0-fwupdplugin-1_0 | Jun 24, 2020 | Jun 15, 2020 |
| Ubuntu | ubuntu-upgrade-fwupdubuntu-upgrade-libfwupd1ubuntu-upgrade-libfwupd2 | Jun 16, 2020 | Jun 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub