Описание
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
A flaw was found in GnuPG. This vulnerability, a stack-based buffer overflow, occurs in the tpm2daemon component when processing PKDECRYPT commands for cryptographic keys secured by a Trusted Platform Module (TPM). A local attacker could exploit this to execute unauthorized code, potentially gaining full control of the system, or disrupt its operation, leading to a denial of service.
Отчет
This is an IMPORTANT vulnerability in GnuPG's tpm2daemon, affecting systems configured to use TPM-backed RSA and ECC keys. A stack-based buffer overflow can occur when processing PKDECRYPT commands, potentially leading to denial of service or arbitrary code execution. Red Hat Enterprise Linux and Fedora systems are impacted if utilizing TPM-backed keys with GnuPG.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnupg2 | Not affected | ||
| Red Hat Enterprise Linux 7 | gnupg2 | Not affected | ||
| Red Hat Enterprise Linux 8 | gnupg2 | Not affected | ||
| Red Hat Enterprise Linux 9 | gnupg2 | Not affected | ||
| Red Hat Enterprise Linux 10 | gnupg2 | Fixed | RHSA-2026:2719 | 16.02.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnupg2 | Fixed | RHSA-2026:2753 | 16.02.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.4 High
CVSS3
Связанные уязвимости
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2da ...
EPSS
8.4 High
CVSS3