Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-42508: LXD and related Canonical tools may accept revoked certificates

CVE-2026-42508 · published 4 months ago
Summary

The cryptographic library used by LXD, snapd, Go, Google Guest Agent and other Canonical packages did not properly check if a signing key had been revoked. This could let an attacker use a revoked key to create seemingly valid signatures, potentially compromising trust. Updating to the latest versions of these packages resolves the issue.

What to do
  • Update canonical golang-go.crypto to version 1:0.0~git20211202.5770296-1ubuntu0.1~esm2.
  • Update canonical golang-go.crypto to version 1:0.19.0-1ubuntu0.1~esm2.
  • Update canonical golang-go.crypto to version 1:0.47.0-1ubuntu0.1~esm1.
  • Update bellsoft podman to version 5.8.4-r0.
  • Update x golang.org/x/crypto to version 0.52.0.
  • Update golang.org x to version 0.52.0.
  • Update x rootio-golang.org/x/crypto to version v0.45.0-root.io.1.
  • Update x golang.org/x/crypto to version v0.45.0-aikido.1.
  • Update x rootio-golang.org/x/crypto to version v0.31.0-root.io.8.
  • Update x golang.org/x/crypto to version v0.31.0-aikido.8.
  • Update x rootio-golang.org/x/crypto to version v0.35.0-root.io.3.
  • Update x golang.org/x/crypto to version v0.35.0-aikido.3.
  • Update x rootio-golang.org/x/crypto to version v0.45.0-root.io.2.
  • Update x golang.org/x/crypto to version v0.45.0-aikido.2.
  • Update x rootio-golang.org/x/crypto to version v0.46.0-root.io.2.
  • Update x golang.org/x/crypto to version v0.46.0-aikido.2.
  • Update canonical lxd to version 2.0.11-0ubuntu1~16.04.4+esm3.
  • Update canonical lxd to version 3.0.3-0ubuntu1~18.04.2+esm3.
  • Update canonical golang-go.crypto to version 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2.
  • Update canonical golang-go.crypto to version 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2.
  • Update debian golang-go.crypto to version 1:0.52.0-1.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.3.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.3.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.5.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.5.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.4.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.4.
  • Update x golang.org/x/crypto to version v0.31.0-aikido.9.
  • Update x rootio-golang.org/x/crypto to version v0.31.0-root.io.9.
  • Update golang crypto to version 0.52.0 or later.
  • Update golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts to version 0.52.0 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:18.04:LTS canonical lxd < 3.0.3-0ubuntu1~18.04.2+esm3
Fix: upgrade to 3.0.3-0ubuntu1~18.04.2+esm3
Ubuntu:Pro:18.04:LTS canonical snapd All versions
Ubuntu:Pro:18.04:LTS canonical golang-go.crypto < 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2
Fix: upgrade to 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2
Ubuntu:Pro:18.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:20.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:20.04:LTS canonical snapd All versions
Ubuntu:Pro:20.04:LTS canonical golang-go.crypto < 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2
Fix: upgrade to 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2
Ubuntu:22.04:LTS canonical google-guest-agent All versions
Ubuntu:22.04:LTS canonical snapd All versions
Ubuntu:Pro:22.04:LTS canonical golang-go.crypto < 1:0.0~git20211202.5770296-1ubuntu0.1~esm2
Fix: upgrade to 1:0.0~git20211202.5770296-1ubuntu0.1~esm2
Ubuntu:24.04:LTS canonical google-guest-agent All versions
Ubuntu:24.04:LTS canonical snapd All versions
Ubuntu:Pro:24.04:LTS canonical golang-go.crypto < 1:0.19.0-1ubuntu0.1~esm2
Fix: upgrade to 1:0.19.0-1ubuntu0.1~esm2
Ubuntu:25.10 canonical golang-go.crypto All versions
Ubuntu:Pro:26.04:LTS canonical golang-go.crypto < 1:0.47.0-1ubuntu0.1~esm1
Fix: upgrade to 1:0.47.0-1ubuntu0.1~esm1
Debian:11 debian golang-go.crypto All versions
Debian:12 debian golang-go.crypto All versions
Debian:13 debian golang-go.crypto All versions
Debian:14 debian golang-go.crypto < 1:0.52.0-1
Fix: upgrade to 1:0.52.0-1
Alpaquita:stream bellsoft osv-scanner >= 2.1.0-r2
Alpaquita:stream bellsoft podman >= 4.5.1-r1, < 5.8.4-r0
Fix: upgrade to 5.8.4-r0
Go x golang.org/x/crypto < 0.52.0
Fix: upgrade to 0.52.0
Ubuntu:Pro:16.04:LTS canonical golang-go.crypto All versions
Ubuntu:Pro:16.04:LTS canonical lxd < 2.0.11-0ubuntu1~16.04.4+esm3
Fix: upgrade to 2.0.11-0ubuntu1~16.04.4+esm3
Ubuntu:Pro:16.04:LTS canonical snapd All versions
Ubuntu:Pro:16.04:LTS canonical google-guest-agent All versions
Ubuntu:25.10 canonical google-guest-agent All versions
Ubuntu:25.10 canonical snapd All versions
Ubuntu:26.04:LTS canonical golang-go.crypto All versions
Ubuntu:26.04:LTS canonical google-guest-agent All versions
Ubuntu:26.04:LTS canonical snapd All versions
– golang crypto < 0.52.0
cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*
go golang.org x < 0.52.0
Fix: upgrade to 0.52.0
Root:Go x rootio-golang.org/x/crypto < v0.45.0-root.io.1
< v0.31.0-root.io.8
< v0.35.0-root.io.3
< v0.45.0-root.io.2
< v0.46.0-root.io.2
< v0.32.0-root.io.3
< v0.32.0-root.io.5
< v0.32.0-root.io.4
< v0.31.0-root.io.9
Fix: upgrade to v0.45.0-root.io.1
Root:Go x golang.org/x/crypto < v0.45.0-aikido.1
< v0.31.0-aikido.8
< v0.35.0-aikido.3
< v0.45.0-aikido.2
< v0.46.0-aikido.2
< v0.32.0-aikido.3
< v0.32.0-aikido.5
< v0.32.0-aikido.4
< v0.31.0-aikido.9
Fix: upgrade to v0.45.0-aikido.1
– golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts < 0.52.0
Alpaquita:23 bellsoft buildah >= 1.28.0-r1
Alpaquita:23 bellsoft containerd >= 1.6.10-r0
Alpaquita:23 bellsoft podman >= 4.3.1-r0
Alpaquita:23 bellsoft skopeo >= 1.10.0-r2
Alpaquita:25 bellsoft buildah >= 1.40.0-r0
Alpaquita:25 bellsoft containerd >= 2.1.1-r0
Alpaquita:25 bellsoft docker-cli-buildx >= 0.24.0-r0
Alpaquita:25 bellsoft google-guest-agent >= 20250521.00-r0
Alpaquita:25 bellsoft osv-scanner >= 2.1.0-r4
Alpaquita:25 bellsoft podman >= 5.5.0-r0
Alpaquita:25 bellsoft skopeo >= 1.18.0-r2
Alpaquita:stream bellsoft buildah >= 1.31.0-r0
Alpaquita:stream bellsoft calicoctl >= 3.31.3-r0
Alpaquita:stream bellsoft cilium-cli >= 0.19.0-r12
Showing 50 of 57. Show the rest
Ecosystem VendorProductAffected versions
Alpaquita:stream bellsoft containerd >= 1.7.2-r1
Alpaquita:stream bellsoft docker-cli-buildx >= 0.11.0-r0
Alpaquita:stream bellsoft etcd >= 3.6.4-r6
Alpaquita:stream bellsoft google-guest-agent >= 20250214.01-r0
Alpaquita:stream bellsoft grype >= 0.100.0-r0
Alpaquita:stream bellsoft helm >= 3.19.0-r4
Alpaquita:stream bellsoft skopeo >= 1.13.0-r1
Original advisory text
CVE-2026-42508 in golang.org/x/crypto - Patched by Root
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
References
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published22 May 2026
Updated3 Oct 2026
First seen22 May 2026
Track software like this
Free during beta