---
title: "CVE-2019-13050\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-13050?format=md
keywords: index, follow
---

# CVE-2019-13050

Publication date 29 June 2019

Last updated 18 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2019-13050?format=md#impact-score)

Toggle side navigation

## Description

Interaction between the sks-keyserver code through 1.2.0 of the SKS
keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG
keyserver configuration line referring to a host on the SKS keyserver
network. Retrieving data from this network may cause a persistent denial of
service, because of a Certificate Spamming Attack.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-13050?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| sks | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| 14.04 LTS trusty | Not in release |
| gnupg | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| 14.04 LTS trusty | Vulnerable, fix deferred |
| gnupg2 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Fixed 2.2.4-1ubuntu1.5 |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-13050?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

this is a weakness in the PGP keyserver design.

---

### [alexmurray](https://launchpad.net/~alexmurray)

gnupg upstream has 2 mitigations for this - firstly, don't import key signatures by default anymore, and to fallback to only import self-signatures on very large keyblocks

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

as of 2020-01-06, there is no ideal fix for this issue
marking this CVE as deferred until a complete fix is available

---

### [sbeattie](https://launchpad.net/~sbeattie)

gnupg mitigations landed in upstream in 2.2.17 with important
fixes in 2.2.18
2.2.19-3ubuntu1 introduced a debian/ubuntu specific change to
use keys.openpgp.org as the default keyserver
any backports to address this issue will be complex and
introduce changes in behavior
sks in debian introduced very basic filtering in
1.1.6+git20210302.c3ba6d5a-1

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

as of 2022-03-22, there is no upstream backport for
gnupg 1.4 series. Backporting from 2.2 is too risky.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| gnupg2 | * Upstream:   <https://dev.gnupg.org/rG15a425a1dfe60bd976b17671aa8e3d9aed12e1c0> * Upstream:   <https://dev.gnupg.org/rGadb120e663fc5e78f714976c6e42ae233c1990b0> * Upstream:   <https://dev.gnupg.org/rGa1f2f38dfb2ba5ed66d3aef66fc3be9b67f9b800> * Upstream:   <https://dev.gnupg.org/rG2b7151b0a57f5fe7d67fd76dfa1ba7a8731642c6> * Upstream:   <https://dev.gnupg.org/rGb6effaf4669b2c3707932e3c5f2f57df886d759e> * Upstream:   <https://dev.gnupg.org/rG3c2cf5ea952015a441ee5701c41dadc63be60d87> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13050)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-13050)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-13050)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-13050)

### Related Ubuntu Security Notices (USN)

+ [USN-5431-1](https://usn.ubuntu.com/USN-5431-1)
+ GnuPG vulnerability
+ 30 May 2022

### Other references

* <https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f>
* <https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html>
* <https://tech.michaelaltfield.net/2019/07/14/mitigating-poisoned-pgp-certificates/>
* <https://www.cve.org/CVERecord?id=CVE-2019-13050>
