In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade gnupg2-debugsourceUpgrade gnupg2-minimalUpgrade gnupg2-minimal-debuginfoUpgrade gnupg2Upgrade gnupg2-debuginfoUpgrade gnupg2-smimeUpgrade gnupg2-smime-debuginfo | Feb 20, 2026 | Jan 27, 2026 |
| Oracle_linux | — | Upgrade gnupg2-smimeUpgrade gnupg2 | Feb 24, 2026 | Jan 27, 2026 |
| Redhat_linux | — | Upgrade gnupg2-debuginfoUpgrade gnupg2-debugsourceUpgrade gnupg2-smimeUpgrade gnupg2-smime-debuginfoUpgrade gnupg2 | Feb 17, 2026 | Jan 27, 2026 |
| Rocky_linux | — | Upgrade gnupg2-debugsourceUpgrade gnupg2Upgrade gnupg2-debuginfoUpgrade gnupg2-smimeUpgrade gnupg2-smime-debuginfo | Feb 26, 2026 | Feb 24, 2026 |
| Suse | — | Upgrade gpg2-langUpgrade dirmngrUpgrade gpg2Upgrade gpg2-tpm | Feb 4, 2026 | Jan 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub