REDHAT-BUG-2461063: Buffer Overflow
Published Apr 23, 2026
·Updated
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcrypkdecrypt.
Affected Software
1 affected component
gnupg Libgcrypt<1.12.2
Event History
Apr 23, 2026
Data Sourced
via Red Hat·05:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Systems using Libgcrypt versions before 1.12.2 are affected when they process crafted ECDH ciphertext through gcry_pk_decrypt. The issue can cause a heap-based buffer overflow and denial of service.
2
What does an attacker need to do to trigger the vulnerability?
An attacker needs to supply crafted ECDH ciphertext that is processed by gcry_pk_decrypt. The provided information does not state that authentication, local access, or a particular service configuration is required.
3
What is the available remediation?
Update Libgcrypt to version 1.12.2 or later. The supplied data does not provide a workaround for environments that cannot update immediately.