https://seclists.org/oss-sec/2025/q4/316: Many vulnerabilities in GnuPG
Published Dec 29, 2025
·Updated
Affected Software
1 affected component
gnupg GnuPG
Frequently Asked Questions
1
What is the severity of GnuPG vulnerability involving RCE?
The severity of the Remote Code Execution (RCE) vulnerability in GnuPG is critical due to its potential for unauthorized system access.
2
How do I fix GnuPG vulnerability #5 related to Remote Code Execution?
To fix the GnuPG vulnerability #5, update to the latest version of GnuPG where the RCE bug has been addressed.
3
What versions of GnuPG are affected by vulnerability #5?
GnuPG versions prior to the latest release that includes the patch for vulnerability #5 are affected by the Remote Code Execution issue.
4
What should I do if I cannot update GnuPG to fix the vulnerability?
If you cannot update GnuPG, consider implementing workarounds such as restricting access to the software or using alternative secure methods for cryptographic tasks.
5
Is there any patch available for the RCE vulnerability in GnuPG?
Yes, a patch for the RCE vulnerability in GnuPG has been made available in the latest update as indicated in the relevant commit.