Updated gnupg2 packages fix security vulnerabilitiy
Publication date: 12 Apr 2025Modification date: 12 Apr 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-30258
Description
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS". (CVE-2025-30258)
References
SRPMS
9/core
- gnupg2-2.3.8-1.3.mga9