← Back

Sequoia Pgp

sequoia-pgp

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Rpm Sequoia
rpm-sequoia

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Sequoia Pgp
3Enterprise Linux
Hardened ImagesRpm Sequoia
Jul 24, 2026
Apr 3, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can t...Show more
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.Show less
1Sequoia Pgp
1Buffered Reader
Jun 17, 2026
Jul 28, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
1Sequoia Pgp
1Sequoia Openpgp
Jun 17, 2026
Jul 28, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
1Sequoia Pgp
1Sequoia Openpgp
Jun 17, 2026
Jul 27, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key typ...Show more
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.Show less