{"id":"GHSA-3r3g-g73x-g593","summary":"coreos-installer improperly verifies GPG signature when decompressing gzipped artifact","details":"### Impact\n\ncoreos-installer fails to correctly verify GPG signatures when decompressing gzip-compressed artifacts.  This allows bypass of signature verification in cases where coreos-installer decompresses a downloaded OS image, allowing an attacker who can modify the OS image to compromise a newly-installed system.\n\nDefault installations from ISO or PXE media in Fedora CoreOS, RHEL CoreOS, and RHEL for Edge are **not** affected, as coreos-installer installs from an OS image shipped as part of the install media.\n\nThese flows are affected:\n\n1.  Installing with `--image-file`, `--image-url`, or `coreos.inst.image_url`.  For example, if a user has a local mirror of installation images, an attacker could replace an image with a gzip-compressed alternative (even if the file extension is `.xz`).  The result:\n\n    ```\n    $ coreos-installer install --image-url http://localhost:8080/image.xz /dev/loop0\n    Downloading image from http://localhost:8080/image.xz\n    Downloading signature from http://localhost:8080/image.xz.sig\n    \u003e Read disk 749.9 MiB/749.9 MiB (100%)\n    gpg: Signature made Mon 20 Sep 2021 02:41:50 PM EDT\n    gpg: using RSA key 8C5BA6990BDB26E19F2A1A801161AE6945719A39\n    gpg: BAD signature from \"Fedora (34) \u003cfedora-34-primary@fedoraproject.org\u003e\" [ultimate]\n    Install complete.\n    ```\n\n    Notice that GPG reports a bad signature, but coreos-installer continues anyway.  Automation that relies on coreos-installer's exit status will not notice either.\n\n2. `coreos-installer download --decompress --image-url`:\n\n    ```\n    $ coreos-installer download --decompress --image-url http://localhost:8080/image.xz\n    \u003e Read disk 749.9 MiB/749.9 MiB (100%)\n    gpg: Signature made Mon 20 Sep 2021 02:41:50 PM EDT\n    gpg: using RSA key 8C5BA6990BDB26E19F2A1A801161AE6945719A39\n    gpg: BAD signature from \"Fedora (34) \u003cfedora-34-primary@fedoraproject.org\u003e\" [ultimate]\n    ./image\n    ```\n\n    Again, coreos-installer reports success.\n\n3. Installing with default parameters, when **not** installing from the image built into live ISO or PXE media, if the hosting service is compromised or if an active attacker gains control of the HTTPS response.\n\n4. `coreos-installer download --decompress` if the hosting service is compromised or if an active attacker gains control of the HTTPS response.\n\n### Patches\n\nThe vulnerability is [fixed](https://github.com/coreos/coreos-installer/pull/659) in coreos-installer 0.10.1.\n\n### Workarounds\n\nFor `coreos-installer download`, do not use the `-d` or `--decompress` options.\n\nFor `coreos-installer install`, manually inspect the stderr output.  If `BAD signature` appears, do not boot from the target disk.  Note, however, that some OS services may have already accessed data on the compromised disk.\n\n### References\n\nFor more information, see [PR 655](https://github.com/coreos/coreos-installer/pull/655).\n\n### For more information\n\nIf you have any questions or comments about this advisory, [open an issue in coreos-installer](https://github.com/coreos/coreos-installer/issues/new/choose) or email the CoreOS [development mailing list](https://lists.fedoraproject.org/archives/list/coreos@lists.fedoraproject.org/).","aliases":["CVE-2021-20319","RUSTSEC-2022-0103"],"modified":"2026-05-07T05:02:22.871764723Z","published":"2021-10-12T16:06:47Z","database_specific":{"nvd_published_at":"2022-03-04T18:15:00Z","cwe_ids":["CWE-347"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-10-11T21:17:04Z"},"references":[{"type":"WEB","url":"https://github.com/coreos/coreos-installer/security/advisories/GHSA-3r3g-g73x-g593"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20319"},{"type":"WEB","url":"https://github.com/coreos/coreos-installer/pull/655"},{"type":"WEB","url":"https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2011862"},{"type":"PACKAGE","url":"https://github.com/coreos/coreos-installer"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0103.html"}],"affected":[{"package":{"name":"coreos-installer","ecosystem":"crates.io","purl":"pkg:cargo/coreos-installer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.10.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-3r3g-g73x-g593/GHSA-3r3g-g73x-g593.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}