In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
References
Configurations
History
No history.
Information
Published : 2025-12-28 17:16
Updated : 2026-01-14 19:16
NVD link : CVE-2025-68973
Mitre link : CVE-2025-68973
CVE.ORG link : CVE-2025-68973
JSON object : View
Products Affected
gnupg
- gnupg
