https://seclists.org/oss-sec/2025/q4/337: Many vulnerabilities in GnuPG
Published Dec 30, 2025
·Updated
Affected Software
1 affected component
gnupg GnuPG
Frequently Asked Questions
1
What is the severity of vulnerability ID GnuPG-2025-001?
The severity of vulnerability ID GnuPG-2025-001 is rated as critical due to its potential to allow plaintext attacks on detached PGP signatures.
2
How do I fix vulnerability ID GnuPG-2025-001?
To fix vulnerability ID GnuPG-2025-001, you should update to the latest version of GnuPG where the vulnerabilities have been patched.
3
What systems are affected by vulnerability ID GnuPG-2025-001?
Vulnerability ID GnuPG-2025-001 affects all versions of GnuPG prior to the patch release addressing this issue.
4
How does vulnerability ID GnuPG-2025-001 impact my data security?
Vulnerability ID GnuPG-2025-001 can compromise the integrity of signatures associated with your data, allowing potential unauthorized access or modifications.
5
Is there a workaround for vulnerability ID GnuPG-2025-001?
Currently, the best workaround for vulnerability ID GnuPG-2025-001 is to avoid the use of detached PGP signatures until an upgrade can be performed.