[PATCH] Hardening: add signature check with rpmcliVerifySignatures
authorAleš Matěj <amatej@redhat.com>
Mon, 29 Mar 2021 07:22:09 +0000 (09:22 +0200)
committerPeter Michael Green <plugwash@raspbian.org>
Sat, 23 Apr 2022 15:26:04 +0000 (16:26 +0100)
commit5c1549a73171f041da01260e8e21745961f2a080
treef76a213d180117c5005156d13abd5b4984f55790
parent85f93cca7aabb4538d226847c32fc72d90302be0
[PATCH] Hardening: add signature check with rpmcliVerifySignatures

This api is not ideal but works for now. We don't have to set
installroot for the used transaction because we set keyring which is
used to retrieve the keys.

= changelog =
msg: Hardening: add signature check with rpmcliVerifySignatures
type: security
resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1932079

CVE-2021-3445
RhBug:1932079
RhBug:1932089
RhBug:1932090

Related: CVE-2021-3421, CVE-2021-20271

Gbp-Pq: Name 0014-Hardening-add-signature-check-with-rpmcliVerifySigna.patch
libdnf/dnf-keyring.cpp