CVE-2025-68973

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnupg:gnupg:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2025-12-28 17:16

Updated : 2026-01-14 19:16


NVD link : CVE-2025-68973

Mitre link : CVE-2025-68973

CVE.ORG link : CVE-2025-68973


JSON object : View

Products Affected

gnupg

  • gnupg
CWE
CWE-675

Multiple Operations on Resource in Single-Operation Context

CWE-787

Out-of-bounds Write