CVE-2025-68973

EUVD-2025-205519
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
gnupggnupg
𝑥
≤ 2.4.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnupg2
bookworm
2.2.40-1.1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
2.2.27-2+deb11u3
fixed
forky
2.4.9-4
fixed
sid
2.4.9-4
fixed
trixie
2.4.7-21+deb13u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dirmngr
suse enterprise desktop 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise sap 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.12.1
fixed
gpg2
suse enterprise desktop 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise sap 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise server 12 SP3
2.0.24-9.17.1
fixed
suse enterprise server 12 SP5
2.0.24-9.17.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.12.1
fixed
gpg2-lang
suse enterprise desktop 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise sap 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise sap 15 SP7
2.4.4-150600.3.12.1
fixed
suse enterprise server 12 SP3
2.0.24-9.17.1
fixed
suse enterprise server 12 SP5
2.0.24-9.17.1
fixed
suse enterprise server 15 SP4
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP5
2.2.27-150300.3.16.1
fixed
suse enterprise server 15 SP6
2.4.4-150600.3.12.1
fixed
suse enterprise server 15 SP7
2.4.4-150600.3.12.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gnupg2
RHEL 8
0:2.2.20-4.el8_10
fixed
RHEL 8.2 AUS
0:2.2.9-1.el8_2.1
fixed
RHEL 8.4 AUS
0:2.2.20-2.el8_4.1
fixed
RHEL 8.6 AUS
0:2.2.20-3.el8_6.1
fixed
RHEL 8.6 E4S
0:2.2.20-3.el8_6.1
fixed
RHEL 8.6 TUS
0:2.2.20-3.el8_6.1
fixed
RHEL 8.8 E4S
0:2.2.20-3.el8_8.1
fixed
RHEL 8.8 TUS
0:2.2.20-3.el8_8.1
fixed
RHEL 9
0:2.3.3-5.el9_7
fixed
gnupg2-smime
RHEL 8
0:2.2.20-4.el8_10
fixed
RHEL 8.2 AUS
0:2.2.9-1.el8_2.1
fixed
RHEL 8.4 AUS
0:2.2.20-2.el8_4.1
fixed
RHEL 8.6 AUS
0:2.2.20-3.el8_6.1
fixed
RHEL 8.6 E4S
0:2.2.20-3.el8_6.1
fixed
RHEL 8.6 TUS
0:2.2.20-3.el8_6.1
fixed
RHEL 8.8 E4S
0:2.2.20-3.el8_8.1
fixed
RHEL 8.8 TUS
0:2.2.20-3.el8_8.1
fixed
RHEL 9
0:2.3.3-5.el9_7
fixed