DEBIAN-CVE-2026-52727

Source
https://security-tracker.debian.org/tracker/CVE-2026-52727
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-52727.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-52727
Upstream
Published
2026-09-17T19:16:49Z
Modified
2026-09-21T18:00:07Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.

References

Affected packages

Debian:13 / lxc-ci

Package

Name
lxc-ci
Purl
pkg:deb/debian/lxc-ci?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0~git20250414.b414478-1
0.0~git20250929.bcfa5c7-1
0.0~git20251222.5d84b29-1
0.0~git20260223.59049ec-1
0.0~git20260522.6454219-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-52727.json"

Debian:14 / lxc-ci

Package

Name
lxc-ci
Purl
pkg:deb/debian/lxc-ci?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0~git20250414.b414478-1
0.0~git20250929.bcfa5c7-1
0.0~git20251222.5d84b29-1
0.0~git20260223.59049ec-1
0.0~git20260522.6454219-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-52727.json"