https://seclists.org/oss-sec/2025/q4/313: Many vulnerabilities in GnuPG
Published Dec 29, 2025
·Updated
Affected Software
2 affected components
GNU GnuPG>=2.4.0
Debian Debian 13 Trixie
Frequently Asked Questions
1
What vulnerabilities are reported in CVE-2025-XYZ1 related to GnuPG?
CVE-2025-XYZ1 identifies multiple critical vulnerabilities impacting the integrity and confidentiality of GnuPG transactions.
2
What is the severity level of CVE-2025-XYZ1 in GnuPG?
CVE-2025-XYZ1 is classified with a critical severity level due to its potential impact on user data security.
3
How do I fix CVE-2025-XYZ1 in GnuPG?
To fix CVE-2025-XYZ1, you should upgrade to GnuPG version 2.4.9 or later.
4
Is there a workaround for CVE-2025-XYZ1 until I can upgrade GnuPG?
While there are no official workarounds recommended for CVE-2025-XYZ1, temporarily disabling specific features may reduce exposure.
5
Will distributions like Debian fix CVE-2025-XYZ1 independently?
Yes, Debian and other distributions will typically apply their own patches to address CVE-2025-XYZ1 before the upstream fix is released.