Advisories ยป MGASA-2026-0197

Updated gnupg2 packages fix security vulnerabilities

Publication date: 11 Jun 2026
Modification date: 11 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-68973 , CVE-2026-24882 , CVE-2026-24883

Description

CVE-2025-68973, armor_filter in g10/armor.c has two increments of an
index variable where one is intended, leading to an out-of-bounds write
for crafted input.
CVE-2026-24882, a stack-based buffer overflow exists in tpm2daemon
during handling of the PKDECRYPT command for TPM-backed RSA and ECC
keys.
CVE-2026-24883, a long signature packet length causes parse_signature to
return success with sig->data[] set to a NULL value, leading to a denial
of service (application crash).
Upstream has still not fixed CVE-2025-68972. We will be tracking the solution
and providing an update to fix it when possible. 
                

References

SRPMS

9/core