In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
2024-01-12T03:15:08.410
2025-06-03T14:15:26.830
Modified
CVSSv3.1: 9.8 (CRITICAL)