https://seclists.org/oss-sec/2026/q3/625: Fwd: [Announce] Libgcrypt 1.12.3 leased
Published Aug 31, 2026
·Updated
Affected Software
1 affected component
gnupg Libgcrypt=1.12.3
Applications that use Libgcrypt to verify Ed25519 signatures with attacker-controlled public keys or signatures are the relevant exposure. The reported effect is process termination, so services that perform such verification may be susceptible to denial of service.
No. The report states that a degenerate or small-order Ed25519 public key can pass the initial curve check and trigger a fatal log_bug during verification without a valid signature.
No. The provided information does not identify affected versions, fixed versions, or a patch status for the reported bug.