Updated gnupg2 packages fix security vulnerabilities
Publication date: 11 Jun 2026Modification date: 11 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-68973 , CVE-2026-24882 , CVE-2026-24883
Description
CVE-2025-68973, armor_filter in g10/armor.c has two increments of an
index variable where one is intended, leading to an out-of-bounds write
for crafted input.
CVE-2026-24882, a stack-based buffer overflow exists in tpm2daemon
during handling of the PKDECRYPT command for TPM-backed RSA and ECC
keys.
CVE-2026-24883, a long signature packet length causes parse_signature to
return success with sig->data[] set to a NULL value, leading to a denial
of service (application crash).
Upstream has still not fixed CVE-2025-68972. We will be tracking the solution
and providing an update to fix it when possible.
References
- https://bugs.mageia.org/show_bug.cgi?id=34934
- https://www.openwall.com/lists/oss-security/2025/12/28/1
- https://ubuntu.com/security/notices/USN-7946-1
- https://www.openwall.com/lists/oss-security/2026/01/27/8
- https://www.openwall.com/lists/oss-security/2026/01/27/11
- https://www.cve.org/CVERecord?id=CVE-2025-68973
- https://www.cve.org/CVERecord?id=CVE-2026-24882
- https://www.cve.org/CVERecord?id=CVE-2026-24883
SRPMS
9/core
- gnupg2-2.3.8-1.5.mga9