CVE-2016-20021: Gentoo Portage
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
Affected products
- Gentoo Portage: before 3.0.47 (fixed in 3.0.47)
Published 2024-01-12. Last modified 2026-06-17.