REDHAT-BUG-2425966: High severity gnupg GnuPG vulnerability
Published Dec 30, 2025
·Updated
In GnuPG through 2.4.8, armorfilter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input.
Affected Software
1 affected component
gnupg GnuPG<2.4.8
Event History
Dec 30, 2025
Data Sourced
via Red Hat·07:12 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2425966?
The severity of REDHAT-BUG-2425966 is classified as high due to the potential for an out-of-bounds write.
2
How do I fix REDHAT-BUG-2425966?
To fix REDHAT-BUG-2425966, users should update GnuPG to version 2.4.9 or later.
3
What systems are affected by REDHAT-BUG-2425966?
Systems running GnuPG versions prior to 2.4.8 are affected by REDHAT-BUG-2425966.
4
What are the consequences of REDHAT-BUG-2425966?
Exploiting REDHAT-BUG-2425966 can lead to arbitrary code execution due to an out-of-bounds write.
5
Is there a workaround for REDHAT-BUG-2425966 until I can update my software?
Currently, there are no known workarounds for REDHAT-BUG-2425966, making an update essential.