Home / mailingsPDF  

[USN-8158-1] Dogtag PKI vulnerability

Posted on 08 April 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8158-1
April 08, 2026

dogtag-pki vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Dogtag PKI could allow unintended access to network resources.

Software Description:
- dogtag-pki: Enterprise-class Certificate Authority

Details:

Fraser Tweedale and Geetika Kapoor discovered that Dogtag PKI could renew a
certificate without proper authentication. An attacker could possibly use
this to repeatedly renew a compromised certificate and maintain
unauthorized access to a system or resource.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
dogtag-pki 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
libsymkey-java 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
libsymkey-jni 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-base 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-base-java 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-ca 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-console 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-kra 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-ocsp 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-server 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-tks 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-tools 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-tps 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
pki-tps-client 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro
python3-pki-base 10.8.3-1ubuntu1+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
dogtag-pki 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
libsymkey-java 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
libsymkey-jni 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-base 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-base-java 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-ca 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-console 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-kra 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-ocsp 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-server 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-tks 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-tools 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-tps 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
pki-tps-client 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro
python3-pki-base 10.6.0-1ubuntu2+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8158-1
CVE-2021-20179

--===============5486716474283627708==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP