CVE-2026-52727

Source
https://cve.org/CVERecord?id=CVE-2026-52727
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52727.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-52727
Aliases
  • GHSA-4h59-f67g-5qxp
Downstream
Published
2026-09-17T18:21:21Z
Modified
2026-09-19T03:46:27Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
lxc-ci: Pacman keyring stored in archlinux image with a private key
Details

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-321"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52727.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "2026-05-28"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/lxc/lxc-ci

Affected ranges

Type
GIT
Repo
https://github.com/lxc/lxc-ci
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52727.json"