https://seclists.org/oss-sec/2026/q3/798: trospective by 'gpg.fail' authors
Published Sep 15, 2026
·Updated
Affected Software
2 affected components
gnupg gpgsm=2.4.9
libgcrypt/libgcrypt<=1.12.2
The reported RCE in gpgsm 2.4.9 is triggered when gpgsm is invoked with both --debug all and --import on a malicious certificate. The provided information does not indicate that a normal gpgsm --import invocation without --debug all is affected.
The gpgsm issue was described as a zero-day that had not been reported to GnuPG. The libgcrypt RSASSA-PSS verification issue was fixed by commit 0d64fc2 and was apparently released in libgcrypt 1.12.3, without a CVE assignment.
The researchers claim the integer underflow and subsequent buffer overflow in RSASSA-PSS verification can lead to RCE through an S/MIME verifier and GnuPG. Their claim depends on a 53-bit preimage attack.