Updated libgcrypt package fixes a security vulnerability
Publication date: 02 Oct 2026Modification date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-2236
Description
Libgcrypt: vulnerable to marvin attack. (CVE-2024-2236)
References
- https://bugs.mageia.org/show_bug.cgi?id=36248
- https://ubuntu.com/security/notices/USN-8711-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2268268
- https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html
- https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt
- https://people.redhat.com/~hkario/marvin/
- https://dev.gnupg.org/T7136
- https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17
- https://www.cve.org/CVERecord?id=CVE-2024-2236
SRPMS
10/core
- libgcrypt-1.11.3-1.1.mga10