PT-2026-5011 · Gnupg · Gnupg

·

CVE-2026-24883

·

Published

2026-01-01

·

Updated

2026-05-27

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.17
Description A long signature packet length can cause the parse signature function to return success while setting the sig->data pointer to a NULL value. This results in a denial of service, specifically an application crash.
Recommendations Update to a version of GnuPG 2.5.17 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24883
ECHO-273B-FD6D-3AFE
JLSEC-2026-566
OPENSUSE-SU-2026:10112-1
OPENSUSE-SU-2026:20136-1
SUSE-SU-2026:20179-1
SUSE-SU-2026:20195-1

Affected Products

Gnupg