Opened 6 months ago
Closed 5 months ago
#23152 closed enhancement (fixed)
libgcrypt-1.12.2
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 6 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
comment:3 by , 6 months ago
| Resolution: | fixed |
|---|---|
| Status: | closed → reopened |
From Werner Koch on gnupg-devel list:
Hello! We are pleased to announce the availability of couple of new Libgcrypt versions: 1.12.2, 1.11.3, and 1.10.4 . It is suggested to use 1.12.2 which is fully compatible with all earlier versions. This version fixes a security bug [T8211] which can be used used to mount a DoS using ECDH encryption (with NIST, Brainpool, X448, or X25519 curves). Note that GnuPG versions since 2.5.7 are not affected by this bug due to the use of a different encryption API. Another security bug [T8208] was fixed in the Dilithium signing algorithm which is available since version 1.12.0.
T8211 bug is not accessible AFAICT
comment:4 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | reopened → new |
comment:5 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Priority: | normal → elevated |
I cannot find a CVE number.
comment:6 by , 5 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
SA-13.0-056 issued
There unfortunately wasn't a CVE assigned for this, which was rather annoying because there is a *small* remote code execution impact, though it is mostly squashed by modern hardening in glibc. However it is still a good denial of service and memory corruption problem. The upstream bug report is now public.
Note:
See TracTickets
for help on using tickets.

Noteworthy changes in version 1.12.2 (2026-04-15) [C27/A7/R2] ------------------------------------------------- * Bug fixes: - Fix possible ECDH buffer overwrite with zeroes. [T8211] - Add a missing bounds check to the Dilithium context handling. [T8208] - Add point validation when using the new KEM interface. [T8212] * Other: - Fix the dead-code of stronger_key_check for RSA. [T8171] Release-info: https://dev.gnupg.org/T8114Fixed at 8fd43b78fd.