PT-2026-5009 · Gnupg · Gnupg

·

CVE-2026-24881

·

Published

2026-01-27

·

Updated

2026-06-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description A specially crafted CMS (S/MIME) EnvelopedData message with an oversized wrapped session key can lead to a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can result in denial of service, and potentially memory corruption leading to remote code execution.
Recommendations Update GnuPG to version 2.5.17 or later.

Exploit

Fix

RCE

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24881
JLSEC-2026-564
OPENSUSE-SU-2026:10112-1

Affected Products

Gnupg