CVE-2017-2623: Red Hat Enterprise Linux

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.

Affected products

  • Red Hat Enterprise Linux: version 7.0 only
  • Rpm-Ostree Rpm-Ostree: before 2017.3 (fixed in 2017.3)
  • Rpm-Ostree Rpm-Ostree-Client: before 2017.3 (fixed in 2017.3)

Published 2018-07-27. Last modified 2026-06-17.