PT-2026-5011 · Gnupg · Gnupg
Aisle Research
+1
·
Published
2026-01-01
·
Updated
2026-02-08
·
CVE-2026-24883
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GnuPG versions prior to 2.5.17
Description
A long signature packet length can cause the
parse signature function to return success while setting the sig->data pointer to a NULL value. This results in a denial of service, specifically an application crash.Recommendations
Update to a version of GnuPG 2.5.17 or later.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnupg