PT-2025-31016 · Unknown · Sequoia-Openpgp
Published
2024-06-26
·
Updated
2025-08-06
·
CVE-2024-58261
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
sequoia-openpgp crate versions 1.13.0 through 1.20.9
Description
The sequoia-openpgp crate for Rust contains a flaw where
RawCertParser operations can enter an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages when encountering an unsupported primary key type.Recommendations
Update to sequoia-openpgp crate version 1.21.0 or later.
Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sequoia-Openpgp