https://seclists.org/oss-sec/2026/q3/625: Fwd: [Announce] Libgcrypt 1.12.3 leased
Published Aug 31, 2026
·Updated
Affected Software
1 affected component
gnupg Libgcrypt=1.12.3
Frequently Asked Questions
1
Which deployments have a practical exposure to this issue?
Applications that use Libgcrypt to verify Ed25519 signatures with attacker-controlled public keys or signatures are the relevant exposure. The reported effect is process termination, so services that perform such verification may be susceptible to denial of service.
2
Does an attacker need a valid Ed25519 signature to trigger the failure?
No. The report states that a degenerate or small-order Ed25519 public key can pass the initial curve check and trigger a fatal log_bug during verification without a valid signature.
3
Can this report confirm which Libgcrypt versions are affected or fixed?
No. The provided information does not identify affected versions, fixed versions, or a patch status for the reported bug.