oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order
oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order Red Hat disclosed CVE-2026-75939 on 21 September 2026 with a CVSS v3.1 score of 7.4. The affected component is openshift4/oc-mirror-plugin-rhel9 in Red Hat OpenShift Container Platform 4. The tool that syncs release images, operator catalogs and related content into a private registry can be made to accept a forged PGP message, and the defect is one of ordering. According to the vendor advisory, oc-mirror has a validation order defect when processing PGP-signed release images. The tool performs the signature error check b
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in