Search CVE reports


Toggle filters

1 – 10 of 45 results


CVE-2026-57062

Low priority

Some fixes available 2 of 3

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-24883

Medium priority
Not affected

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-24882

Medium priority
Not affected

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-24881

Medium priority
Not affected

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged...

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-68973

High priority
Fixed

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

2 affected packages

gnupg, gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg — — — — —
gnupg2 — Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-68972

Medium priority
Ignored

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the...

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-30258

Medium priority
Fixed

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain...

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-3219

Low priority
Ignored

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

2 affected packages

gnupg, gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg — — Not in release Not in release Not in release
gnupg2 — Ignored Ignored Ignored Ignored
Show less packages

CVE-2022-34903

Medium priority
Fixed

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

2 affected packages

gnupg, gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg — — Not in release Not in release Not in release
gnupg2 — — Fixed Fixed Fixed
Show less packages

CVE-2020-25125

Medium priority
Not affected

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow...

1 affected package

gnupg2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg2 — — — Not affected Not affected
Show less packages