PT-2026-5009 · Gnupg · Gnupg
Openai Security Research
·
Published
2026-01-27
·
Updated
2026-03-10
·
CVE-2026-24881
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GnuPG versions prior to 2.5.17
Description
A specially crafted CMS (S/MIME) EnvelopedData message with an oversized wrapped session key can lead to a stack-based buffer overflow in
gpg-agent during PKDECRYPT--kem=CMS handling. This can result in denial of service, and potentially memory corruption leading to remote code execution.Recommendations
Update GnuPG to version 2.5.17 or later.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnupg