https://seclists.org/oss-sec/2025/q4/301: Many vulnerabilities in GnuPG
Published Dec 28, 2025
·Updated
Affected Software
1 affected component
gnupg GnuPG>=2.5.13<2.5.14
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX related to GnuPG?
The severity of CVE-2025-XXXX is critical due to the potential for remote code execution.
2
How do I fix CVE-2025-XXXX in GnuPG?
To fix CVE-2025-XXXX, upgrade to the latest patched version of GnuPG as recommended in the security advisory.
3
What versions of GnuPG are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects versions prior to 2.5.15 of GnuPG.
4
Is there a workaround for CVE-2025-XXXX in GnuPG?
Currently, there are no reliable workarounds for CVE-2025-XXXX; upgrading is the recommended action.
5
When was CVE-2025-XXXX publicly disclosed?
CVE-2025-XXXX was publicly disclosed on December 28, 2025.