https://seclists.org/oss-sec/2026/q3/628: Fwd: [Announce] Libgcrypt 1.12.3 leased
Published Aug 31, 2026
·Updated
Affected Software
1 affected component
gnupg Libgcrypt=1.12.3
The attacker must be able to supply a degenerate or small-order Ed25519 public key to Libgcrypt's Ed25519 signature-verification path. The point passes the initial on-curve check but reaches a fatal internal arithmetic assertion during scalar multiplication.
The reported behavior is a fatal log_bug condition, so the issue can cause a denial of service in software that performs verification using an attacker-supplied Ed25519 public key.
The announcement identifies Libgcrypt 1.12.3 as released and states that this issue, tracked as T8380, was fixed.