Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24881

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
EPSS Низкий

Описание

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnupg:gnupg:*:*:*:*:-:*:*:*
Версия от 2.5.13 (включая) до 2.5.17 (исключая)
cpe:2.3:a:gpg4win:gpg4win:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.1 (исключая)

EPSS

Процентиль: 74%
0.01654
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-121
CWE-121

Связанные уязвимости

CVSS3: 8.1
ubuntu
7 месяцев назад

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

CVSS3: 8.1
redhat
7 месяцев назад

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

CVSS3: 8.1
debian
7 месяцев назад

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message c ...

CVSS3: 8.1
github
7 месяцев назад

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

EPSS

Процентиль: 74%
0.01654
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-121
CWE-121