Advisories ยป MGASA-2025-0133

Updated gnupg2 packages fix security vulnerabilitiy

Publication date: 12 Apr 2025
Modification date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-30258

Description

In GnuPG before 2.5.5, if a user chooses to import a certificate with
certain crafted subkey data that lacks a valid backsig or that has
incorrect usage flags, the user loses the ability to verify signatures
made from certain other signing keys, aka a "verification DoS".
(CVE-2025-30258)
                

References

SRPMS

9/core