Where
-Infinity
0

Vendor Risk Score

See how gpg4win compares to other vendors in security performance

View Risk Score →
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

First published (updated )
Severity
9.8
EPSS
0.13%
Buffer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

First published (updated )
Severity
9.8
Integer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A bug found in libksba, the library used by GnuPG for parsing the ASN.1 structures as used by S/MIME. The bug affects all versions of Libksba before 1.6.2 and may be used for remote code execution.

https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html https://dev.gnupg.org/T6230 https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b https://lwn.net/Articles/911467/

1 / 2
Source: Red Hat
First published (updated )
Severity
8.4
EPSS
0.01%
Buffer Overflow
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.

First published (updated )
Severity
5.5
EPSS
0.01%
Null Pointer Dereference
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

In GnuPG before 2.5.17, a long signature packet length causes parsesignature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

First published (updated )
Severity
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P

gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature.

First published (updated )

GnuPG 2.5.17 has been released to fix a possible RCE: https://dev.gnupg.org/T8044 ("gpg-agent stack buffer overflow in pkdecrypt using KEM")

[Description for this one at the end, for the full quoted advisory.]

There's two other security-relevant bugs too: https://dev.gnupg.org/T8045 ("Stack-based buffer overflow in TPM2 PKDECRYPT") A stack-based buffer overflow exists in GnuPG’s tpm2daemon when handling the PKDECRYPT command for TPM-backed RSA and ECC keys. A local attacker who can access the daemon’s Assuan socket can send an oversized ciphertext and trigger memory corruption, resulting in a crash and potentially arbitrary code execution. When a user stores private keys inside a TPM, GnuPG runs a helper process called tpm2daemon to perform cryptographic operations on their behalf. Other GnuPG components communicate with this daemon over Assuan, a local IPC protocol. During a PKDECRYPT request, tpm2daemon copies the attacker-supplied ciphertext into fixed-size TPM work buffers without validating that the ciphertext fits. If the supplied ciphertext is larger than the TPM buffer, the copy operation writes past the end of the stack buffer and corrupts adjacent stack memory. This affects both supported TPM decrypt paths: RSA (tpm2rsadecrypt) and ECC (tpm2eccdecrypt). Because the overflow occurs on the stack and is attacker-controlled, it is potentially exploitable for code execution inside the tpm2daemon process. https://dev.gnupg.org/T8049 ("Null pointer dereference with overlong signature packet") Overlong signature packet length causes parsesignature to return success with sig->data[] left NULL, leading to a crash in later consumers. The advisory is at https://dev.gnupg.org/T7996#212268 (not yet on gnupg-announce ML). Quoting that, which discusses the main bug (T8044): These versions are affected:

GnuPG 2.5.16 (released 2025-12-30) GnuPG 2.5.15 (released 2025-12-29) GnuPG 2.5.14 (released 2025-11-19) GnuPG 2.5.13 (released 2025-10-22) Gpg4win 5.0.0 (released 2026-01-14) Gpg4win 5.0.0-beta479 (released 2026-01-02) Gpg4win 5.0.0-beta476 (released 2025-12-22) Gpg4win 5.0.0-beta395 (released 2025-10-22)

All other versions are not affected.

A crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack buffer overflow in gpg-agent during the PKDECRYPT--kem=CMS handling. This can easily be used for a DoS but, worse, the memory corruption can very likley also be used to mount a remote code execution attack.

A CVE-id has not been assigned. We track this bug as T8044 under https://dev.gnupg.org/T8044. This vulnerability was discovered by: OpenAI Security Research. Their report was received on 2026-01-18; fixed versions released 2026-01-27.

Solution:

If an affected GnuPG version is used please update ASAP to the new version 2.5.17.

If an affected version of Gpg4win is used please update ASAP to the new version 5.0.1.

If an immediate update is not possible please remove the gpgsm or gpgsm.exe binary, this way the the bug can't be remotely triggered. sam

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203