PT-2026-34640 · Gnupg · Libgcrypt

Published

2026-04-23

·

Updated

2026-04-23

·

CVE-2026-41989

CVSS v3.1

6.7

Medium

AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry pk decrypt.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-41989

Affected Products

Libgcrypt