Mageia alert MGASA-2025-0133 (gnupg2)
From: | Mageia Updates <updates-announce@ml.mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2025-0133: Updated gnupg2 packages fix security vulnerabilitiy | |
Date: | Sat, 12 Apr 2025 06:24:30 +0200 | |
Message-ID: | <20250412042430.C66AEA0153@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2025-0133 - Updated gnupg2 packages fix security vulnerabilitiy Publication date: 12 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0133.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-30258 Description: In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS". (CVE-2025-30258) References: - https://bugs.mageia.org/show_bug.cgi?id=34165 - https://ubuntu.com/security/notices/USN-7412-1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-3... SRPMS: - 9/core/gnupg2-2.3.8-1.3.mga9