https://seclists.org/oss-sec/2026/q3/625: Fwd: [Announce] Libgcrypt 1.12.3 leased

Published Aug 31, 2026
·
Updated

Affected Software

1 affected component
gnupg Libgcrypt=1.12.3

Frequently Asked Questions

1

Which deployments have a practical exposure to this issue?

Applications that use Libgcrypt to verify Ed25519 signatures with attacker-controlled public keys or signatures are the relevant exposure. The reported effect is process termination, so services that perform such verification may be susceptible to denial of service.

2

Does an attacker need a valid Ed25519 signature to trigger the failure?

No. The report states that a degenerate or small-order Ed25519 public key can pass the initial curve check and trigger a fatal log_bug during verification without a valid signature.

3

Can this report confirm which Libgcrypt versions are affected or fixed?

No. The provided information does not identify affected versions, fixed versions, or a patch status for the reported bug.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203