CVE-2025-30258

EUVD-2025-6762
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
gnupggnupg
𝑥
< 2.4.8
gnupggnupg
2.5.0 ≤
𝑥
< 2.5.5
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dirmngr
suse enterprise desktop 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise desktop 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.13.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.9.1
fixed
gpg2
suse enterprise desktop 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise desktop 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.13.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.9.1
fixed
gpg2-lang
suse enterprise desktop 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise desktop 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.13.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.9.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.9.1
fixed