PT-2026-34640 · Libgcrypt+2 · Libgcrypt+2

CVE-2026-41989

·

Publicado

2026-04-07

·

Atualizado

2026-07-24

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Libgcrypt versões anteriores a 1.12.2
Description Um estouro de buffer baseado em heap e a negação de serviço podem ocorrer ao processar texto cifrado ECDH manipulado através da função gcry pk decrypt().
Recommendations Atualize para a versão 1.12.2 ou posterior.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07879
CVE-2026-41989
ECHO-AFBA-F32F-E1D7
JLSEC-2026-496
OESA-2026-2345
OESA-2026-2346
OESA-2026-2347
OESA-2026-2348
OPENSUSE-SU-2026:21387-1
RHSA-2026:8466
SUSE-SU-2026:22760-1
SUSE-SU-2026:22826-1
SUSE-SU-2026:22907-1
SUSE-SU-2026:22919-1
SUSE-SU-2026:3182-1
USN-8319-1

Produtos afetados

Libgcrypt
Linuxmint
Ubuntu