https://seclists.org/oss-sec/2025/q4/302: Many vulnerabilities in GnuPG
Published Dec 28, 2025
·Updated
Affected Software
1 affected component
gnupg GnuPG
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is considered to have a high severity due to its ability to allow remote code execution.
2
How do I fix CVE-2025-XXXX?
You can fix CVE-2025-XXXX by updating GnuPG to the latest version where the vulnerability has been patched.
3
What versions of GnuPG are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects multiple versions of GnuPG prior to the security update released following its disclosure.
4
Is CVE-2025-XXXX a zero-day vulnerability?
Yes, CVE-2025-XXXX is classified as a zero-day vulnerability, meaning it was exploited before the fix was released.
5
What are the risks associated with CVE-2025-XXXX?
The risks associated with CVE-2025-XXXX include potential unauthorized access and control over affected systems.