PT-2026-5010 · Gnupg · Gnupg

·

CVE-2026-24882

·

Published

2026-01-01

·

Updated

2026-06-30

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description GnuPG is a tool for encrypting data and creating digital signatures. A stack-based buffer overflow exists in the tpm2daemon component when handling the PKDECRYPT command for TPM-backed RSA and ECC keys. This issue could allow for arbitrary code execution. The vulnerability affects systems utilizing TPM-backed RSA/ECC key decryption operations.
Recommendations Upgrade to GnuPG version 2.5.17 or later.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:2719
AZL-75266
AZL-76146
CVE-2026-24882
ECHO-CC02-A477-2575
JLSEC-2026-565
OESA-2026-1300
OESA-2026-1301
OESA-2026-1302
OESA-2026-1336
OPENSUSE-SU-2026:10112-1
OPENSUSE-SU-2026:20136-1
RHSA-2026:2719
RHSA-2026:2753
SUSE-SU-2026:0434-1
SUSE-SU-2026:20179-1
SUSE-SU-2026:20195-1
SUSE-SU-2026:20444-1
SUSE-SU-2026:20487-1

Affected Products

Gnupg