USN-7412-1: GnuPG vulnerability
Published Apr 3, 2025
·Updated
It was discovered that GnuPG incorrectly handled importing keys with certain crafted subkey data. If a user or automated system were tricked into importing a specially crafted key, a remote attacker may prevent users from importing other keys in the future.
Affected Software
24 affected componentsFixes available
All of the following
ubuntu/gnupg<2.4.4-2ubuntu18.2
2.4.4-2ubuntu18.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/gnupg2<2.4.4-2ubuntu18.2
2.4.4-2ubuntu18.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/gpg<2.4.4-2ubuntu18.2
2.4.4-2ubuntu18.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/gnupg<2.4.4-2ubuntu17.2
2.4.4-2ubuntu17.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/gnupg2<2.4.4-2ubuntu17.2
2.4.4-2ubuntu17.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/gpg<2.4.4-2ubuntu17.2
2.4.4-2ubuntu17.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/gnupg<2.2.27-3ubuntu2.3
2.2.27-3ubuntu2.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/gnupg2<2.2.27-3ubuntu2.3
2.2.27-3ubuntu2.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/gpg<2.2.27-3ubuntu2.3
2.2.27-3ubuntu2.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/gnupg<2.2.19-3ubuntu2.4
2.2.19-3ubuntu2.4
Ubuntu Ubuntu=20.04
All of the following
ubuntu/gnupg2<2.2.19-3ubuntu2.4
2.2.19-3ubuntu2.4
Ubuntu Ubuntu=20.04
All of the following
ubuntu/gpg<2.2.19-3ubuntu2.4
2.2.19-3ubuntu2.4
Ubuntu Ubuntu=20.04
Event History
Apr 3, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7412-1?
The severity of USN-7412-1 is considered medium.
2
How do I fix USN-7412-1?
To fix USN-7412-1, upgrade GnuPG to version 2.4.4-2ubuntu18.2 or higher for affected Ubuntu versions.
3
What systems are affected by USN-7412-1?
USN-7412-1 affects Ubuntu 20.04, 22.04, and 24.04 systems running specific versions of GnuPG.
4
What kind of attacks are possible due to USN-7412-1?
A remote attacker may exploit USN-7412-1 to prevent users from importing other keys after being tricked into importing a malicious key.
5
Is there a way to mitigate the risk of USN-7412-1?
Mitigation for USN-7412-1 includes avoiding the import of untrusted keys and keeping software updated.