Opened 8 months ago

Closed 8 months ago

Last modified 8 months ago

#22702 closed enhancement (fixed)

gnupg-2.5.17

Reported by: Bruce Dubbs Owned by: Joe Locash
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Joe Locash, 8 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 8 months ago

Priority: normal → high

comment:3 by Joe Locash, 8 months ago

Fixed at b80562156a.

Leaving open for security advisory.

comment:4 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

comment:5 by Douglas R. Reno, 8 months ago

I've got some new information on this one! On oss-security (see ​https://www.openwall.com/lists/oss-security/2026/01/27/11), CVEs were assigned:

  • CVE-2026-24881 (gpg-agent stack buffer overflow in pkdecrypt using KEM)
  • CVE-2026-24882 (Stack-based buffer overflow in TPM2 `PKDECRYPT)
  • CVE-2026-24883 (Null pointer dereference with overlong signature packet)
Last edited 8 months ago by Douglas R. Reno (previous) (diff)

comment:6 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-083 issued

Note: See TracTickets for help on using tickets.