CVE Vulnerabilities

CVE-2022-39237

Improper Verification of Cryptographic Signature

Published: Oct 06, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the github.com/sylabs/sif/v2/pkg/integrity package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade. Users unable to upgrade may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Singularity_image_format Sylabs * 2.8.1 (excluding)
Golang-github-sylabs-sif Ubuntu kinetic *
Golang-github-sylabs-sif Ubuntu lunar *
Golang-github-sylabs-sif Ubuntu mantic *
Golang-github-sylabs-sif Ubuntu trusty *
Golang-github-sylabs-sif Ubuntu xenial *
Singularity-container Ubuntu bionic *
Singularity-container Ubuntu trusty *
Singularity-container Ubuntu xenial *

References