https://seclists.org/oss-sec/2025/q4/300: Many vulnerabilities in GnuPG
Published Dec 28, 2025
·Updated
Affected Software
1 affected component
gnupg GnuPG
Frequently Asked Questions
1
What is the severity of CVE-2025-30001?
The severity of CVE-2025-30001 is critical due to its potential risk for remote code execution.
2
How do I fix CVE-2025-30001?
To fix CVE-2025-30001, update to the latest version of GnuPG as released by the developers.
3
What are the main vulnerabilities described in CVE-2025-30001?
CVE-2025-30001 primarily involves issues with the unreliable display of signed and verified content.
4
Is CVE-2025-30001 actively being addressed by the GnuPG team?
Yes, the GnuPG team has acknowledged the issues and has released fixes for the critical vulnerabilities including CVE-2025-30001.
5
How can I determine if I am affected by CVE-2025-30001?
You can determine if you are affected by CVE-2025-30001 by checking your current GnuPG version against the versions listed in the vulnerability advisory.