CVE-2022-39237: Digital Signature Hash Algorithms Not Validated in sylabs/sif
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the github.com/sylabs/sif/v2/pkg/integrity package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade. Users unable to upgrade may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39237.
What is the severity of CVE-2022-39237?
CVE-2022-39237 has a severity of critical.
What is the affected software of CVE-2022-39237?
The affected software of CVE-2022-39237 is Sylabs Singularity Image Format versions up to and excluding 2.8.1.
Is there a patch available for CVE-2022-39237?
Yes, a patch is available in version >=2.8.1.
What are the references for CVE-2022-39237?
The references for CVE-2022-39237 are: [GitHub Commit](https://github.com/sylabs/sif/commit/07fb86029a12e3210f6131e065570124605daeaa), [GitHub Security Advisory](https://github.com/sylabs/sif/security/advisories/GHSA-m5m3-46gj-wch8), [Gentoo GLSA](https://security.gentoo.org/glsa/202210-19).