PT-2026-34640 · Libgcrypt+2 · Libgcrypt+2

Published

2026-04-07

·

Updated

2026-05-27

·

CVE-2026-41989

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libgcrypt versions prior to 1.12.2
Description A heap-based buffer overflow and denial of service can occur when processing crafted ECDH ciphertext through the gcry pk decrypt() function.
Recommendations Update to version 1.12.2 or later.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07879
CVE-2026-41989
ECHO-AFBA-F32F-E1D7
JLSEC-2026-496
OESA-2026-2345
OESA-2026-2346
OESA-2026-2347
OESA-2026-2348
RHSA-2026:8466
USN-8319-1

Affected Products

Libgcrypt
Linuxmint
Ubuntu