PT-2026-5009 · Gnupg · Gnupg

Openai Security Research

·

Published

2026-01-27

·

Updated

2026-03-10

·

CVE-2026-24881

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description A specially crafted CMS (S/MIME) EnvelopedData message with an oversized wrapped session key can lead to a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can result in denial of service, and potentially memory corruption leading to remote code execution.
Recommendations Update GnuPG to version 2.5.17 or later.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-24881
OPENSUSE-SU-2026:10112-1

Affected Products

Gnupg