A curious incident has come to light. According to an official Mozilla Security Blog post, the GPG signing key used to authenticate Firefox for Linux and Thunderbird for Linux packages has been rotated. The trigger was an unsettling discovery: for reasons that remain unexplained, Mozilla appears to have inadvertently committed a copy of the previously used signing subkey to a private GitHub repository.
Audit Finds No Unauthorized Access – But Questions Remain
Mozilla’s review of existing audit logs uncovered no evidence of unauthorized access to the key during the period it resided in the repository. Access to that repository was restricted to a small number of Mozilla employees – all of whom already held legitimate authorization to use the key.
Nevertheless, Mozilla has not offered a public explanation for how or why the subkey was uploaded to the private repository in the first place. That silence leaves an open question hanging over what would otherwise be a contained incident.
Key Rotation and Revocation: What Mozilla Has Done
As a precautionary security measure, Mozilla has rotated the GPG signing subkey. Furthermore, the old signing subkey has been formally revoked.
Users who verify package signatures must now take action. Before performing any signature verification, they must remove the old key and import the new one. Once the new key is successfully imported, normal verification of installation packages can proceed as before.
Action Required: Who Needs to Do What
The steps users need to follow depend on how they interact with Firefox and Thunderbird packages.
Manual GPG Signature Verification
Users who manually verify GPG signatures must import both the new signing key and the revocation information for the old key. Skipping either step will result in verification failures.
Firefox RPM Package Users
Users who install Firefox via RPM packages may need to perform additional manual steps. Mozilla’s help documentation provides specific guidance for this scenario.
New GPG Key Details
The following technical details apply to the newly issued signing key. Users and system administrators should record these values for verification purposes.
- GPG Key Fingerprint: 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353
- Subkey Fingerprint: 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3
- Valid Until: August 5, 2028
- Obtain the Key: Download the new GPG signing key directly from Mozilla’s archive
Linux users who rely on signed Firefox or Thunderbird packages should update their keyrings promptly to avoid any disruption to their verification workflows.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.