Updated gnupg2 packages fix security vulnerabilitiy
Publication date: 12 Apr 2025Modification date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-30258
Description
In GnuPG before 2.5.5, if a user chooses to import a certificate with
certain crafted subkey data that lacks a valid backsig or that has
incorrect usage flags, the user loses the ability to verify signatures
made from certain other signing keys, aka a "verification DoS".
(CVE-2025-30258)
References
SRPMS
9/core
- gnupg2-2.3.8-1.3.mga9