CVE-2016-20021: Gentoo Portage

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.

Affected products

  • Gentoo Portage: before 3.0.47 (fixed in 3.0.47)

Published 2024-01-12. Last modified 2026-06-17.