The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agentUpgrade amazon-cloudwatch-agentUpgrade nerdctl-debuginfoUpgrade containerd-debuginfoUpgrade rclone-debuginfoUpgrade containerd-stressUpgrade containerdUpgrade nerdctlUpgrade rcloneUpgrade docker-debuginfoUpgrade runfinch-finchUpgrade docker | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade docker-debuginfoUpgrade rcloneUpgrade dockerUpgrade containerd-stress-debuginfoUpgrade runfinch-finchUpgrade rclone-debuginfoUpgrade containerd-debuginfoUpgrade amazon-cloudwatch-agentUpgrade containerd-debugsourceUpgrade amazon-ssm-agentUpgrade nerdctlUpgrade docker-debugsourceUpgrade containerdUpgrade rclone-debugsourceUpgrade containerd-stress | Jun 9, 2026 | May 22, 2026 |
| Redhat_linux | — | Upgrade flightctl-cliUpgrade flightctl-selinuxUpgrade flightctl-servicesUpgrade flightctl-agentUpgrade flightctl-observabilityNo solution exists | Aug 4, 2026 | May 22, 2026 |
| Ubuntu | — | Upgrade google-guest-agent (Ubuntu Pro)Upgrade golang-golang-x-crypto-dev (Ubuntu Pro)Upgrade google-guest-agentUpgrade golang-go.crypto-dev (Ubuntu Pro) | Jun 18, 2026 | Jun 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub