PT-2026-5010 · Gnupg · Gnupg

Openai Security Research

·

Published

2026-01-01

·

Updated

2026-03-15

·

CVE-2026-24882

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description GnuPG is a tool for encrypting data and creating digital signatures. A stack-based buffer overflow exists in the tpm2daemon component when handling the PKDECRYPT command for TPM-backed RSA and ECC keys. This issue could allow for arbitrary code execution. The vulnerability affects systems utilizing TPM-backed RSA/ECC key decryption operations.
Recommendations Upgrade to GnuPG version 2.5.17 or later.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:2719
AZL-75266
AZL-76146
CVE-2026-24882
ECHO-CC02-A477-2575
OESA-2026-1300
OESA-2026-1301
OESA-2026-1302
OESA-2026-1336
OPENSUSE-SU-2026:10112-1
OPENSUSE-SU-2026:20136-1
RHSA-2026:2719
RHSA-2026:2753
SUSE-SU-2026:0434-1
SUSE-SU-2026:20179-1
SUSE-SU-2026:20195-1
SUSE-SU-2026:20444-1
SUSE-SU-2026:20487-1

Affected Products

Gnupg