https://seclists.org/oss-sec/2026/q3/782: trospective by 'gpg.fail' authors
Affected Software
Frequently Asked Questions
Are these two issues remediated in the same way?
No. The libgcrypt RSASSA-PSS verification issue was fixed in commit 0d64fc2 and apparently released in libgcrypt 1.12.3. The reported gpgsm issue was described as an unreported zero-day, with no fix identified in the provided information.
Does the reported gpgsm issue affect normal certificate imports?
The available proof of concept uses gpgsm 2.4.9 invoked as "gpgsm --debug all --import bad.cert". The provided information does not establish whether imports without the "--debug all" option are affected.
What attacker-controlled input is needed for the reported gpgsm code-execution path?
An attacker would need a target to import a malicious certificate file using the reported gpgsm invocation. If patching is unavailable, avoid importing untrusted certificate files with that debug-enabled command path.
Where might the libgcrypt issue be reachable?
The issue is in RSASSA-PSS signature verification and is claimed to permit code execution through the S/MIME verifier and GnuPG with a 53-bit preimage attack. The provided information does not identify the hash algorithm or provide additional exploitation conditions.