#22702 closed enhancement (fixed)
gnupg-2.5.17
| Reported by: | Bruce Dubbs | Owned by: | Joe Locash |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 8 months ago
| Priority: | normal → high |
|---|
comment:5 by , 8 months ago
I've got some new information on this one! On oss-security (see https://www.openwall.com/lists/oss-security/2026/01/27/11), CVEs were assigned:
- CVE-2026-24881 (gpg-agent stack buffer overflow in pkdecrypt using KEM)
- CVE-2026-24882 (Stack-based buffer overflow in TPM2 `PKDECRYPT)
- CVE-2026-24883 (Null pointer dereference with overlong signature packet)
Note:
See TracTickets
for help on using tickets.

See https://lists.gnupg.org/pipermail/gnupg-announce/2026q1/000501.html
This is a critical update.