PT-2026-5011 · Gnupg · Gnupg

Aisle Research

+1

·

Published

2026-01-01

·

Updated

2026-02-08

·

CVE-2026-24883

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description A long signature packet length can cause the parse signature function to return success while setting the sig->data pointer to a NULL value. This results in a denial of service, specifically an application crash.
Recommendations Update to a version of GnuPG 2.5.17 or later.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-24883
ECHO-273B-FD6D-3AFE
OPENSUSE-SU-2026:10112-1
OPENSUSE-SU-2026:20136-1
SUSE-SU-2026:20179-1
SUSE-SU-2026:20195-1

Affected Products

Gnupg