GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gnupg | Aug 30, 2017 | Oct 9, 2013 |
| Centos_linux | — | Upgrade gnupg2Upgrade gnupgUpgrade gnupg2-smime | Dec 1, 2016 | Oct 9, 2013 |
| Debian | — | Upgrade gnupgUpgrade gnupg2 | Jul 30, 2024 | Oct 10, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 19, 2016 |
| Gentoo Linux | — | Upgrade app-crypt/gnupg.Upgrade dev-libs/libgcrypt. | Oct 30, 2017 | Oct 9, 2013 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Oct 9, 2013 |
| Oracle_linux | — | Upgrade gnupg2Upgrade gnupg2-smime | Oct 16, 2024 | Oct 10, 2013 |
| Suse | — | Upgrade gpgUpgrade gpg2Upgrade gpg2-lang | Dec 12, 2013 | Oct 9, 2013 |
| Ubuntu | — | Upgrade gnupg2Upgrade gnupg | Nov 8, 2024 | Oct 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub