CVE-2026-39833

Public on 2026-05-22
Modified on 2026-05-29
Description
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-cloudwatch-agent Pending Fix
Amazon Linux 2023 amazon-cloudwatch-agent Pending Fix
Amazon Linux 2 - Ecs Extra containerd Pending Fix
Amazon Linux 2 - Docker Extra containerd 2026-06-08 ALAS2DOCKER-2026-127 Fixed
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra containerd 2026-06-08 ALAS2NITRO-ENCLAVES-2026-109 Fixed
Amazon Linux 2023 containerd 2026-06-08 ALAS2023-2026-1784 Fixed
Amazon Linux 2 - Ecs Extra docker Pending Fix
Amazon Linux 2 - Docker Extra docker 2026-06-08 ALAS2DOCKER-2026-126 Fixed
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra docker 2026-06-08 ALAS2NITRO-ENCLAVES-2026-108 Fixed
Amazon Linux 2023 docker 2026-06-08 ALAS2023-2026-1783 Fixed
Amazon Linux 2023 git-lfs Not Affected
Amazon Linux 2 - Core nerdctl 2026-06-08 ALAS2-2026-3334 Fixed
Amazon Linux 2023 nerdctl 2026-06-08 ALAS2023-2026-1788 Fixed
Amazon Linux 2 - Core rclone 2026-06-08 ALAS2-2026-3348 Fixed
Amazon Linux 2023 rclone 2026-06-08 ALAS2023-2026-1810 Fixed
Amazon Linux 2 - Docker Extra runfinch-finch 2026-06-08 ALAS2DOCKER-2026-128 Fixed
Amazon Linux 2023 runfinch-finch 2026-06-08 ALAS2023-2026-1809 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N