Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57062

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.

Отчет

A Low-impact flaw in GnuPG's gpgsm component accepts an incorrect AES-GCM authentication tag length in CMS messages. This compromises cryptographic data integrity, though confidentiality and availability are unaffected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gnupg2Fix deferred
Red Hat Enterprise Linux 6gnupg2Out of support scope
Red Hat Enterprise Linux 7gnupg2Out of support scope
Red Hat Enterprise Linux 8gnupg2Fix deferred
Red Hat Enterprise Linux 9gnupg2Fix deferred
Red Hat Hardened Imagesgnupg2Affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2491859GnuPG: Incorrect cryptographic message parsing

EPSS

Процентиль: 4%
0.00142
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
около 1 месяца назад

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

CVSS3: 2.9
nvd
около 1 месяца назад

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

CVSS3: 2.9
msrc
около 1 месяца назад

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

CVSS3: 2.9
debian
около 1 месяца назад

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2 ...

suse-cvrf
14 дней назад

Security update for gpg2

EPSS

Процентиль: 4%
0.00142
Низкий

2.9 Low

CVSS3