Mageia alert MGASA-2026-0197 (gnupg2)
| From: | Mageia Updates <updates-announce@ml.mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2026-0197: Updated gnupg2 packages fix security vulnerabilities | |
| Date: | Thu, 11 Jun 2026 18:56:37 +0200 | |
| Message-ID: | <20260611165637.2F400A0E33@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2026-0197 - Updated gnupg2 packages fix security vulnerabilities Publication date: 11 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0197.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-68973, CVE-2026-24882, CVE-2026-24883 Description: CVE-2025-68973, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. CVE-2026-24882, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys. CVE-2026-24883, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash). Upstream has still not fixed CVE-2025-68972. We will be tracking the solution and providing an update to fix it when possible. References: - https://bugs.mageia.org/show_bug.cgi?id=34934 - https://www.openwall.com/lists/oss-security/2025/12/28/1 - https://ubuntu.com/security/notices/USN-7946-1 - https://www.openwall.com/lists/oss-security/2026/01/27/8 - https://www.openwall.com/lists/oss-security/2026/01/27/11 - https://www.cve.org/CVERecord?id=CVE-2025-68973 - https://www.cve.org/CVERecord?id=CVE-2026-24882 - https://www.cve.org/CVERecord?id=CVE-2026-24883 SRPMS: - 9/core/gnupg2-2.3.8-1.5.mga9
