CVE-2026-41989
EUVD-2026-2519223.04.2026, 05:16
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnupg | libgcrypt | 1.8.8 ≤ 𝑥 < 1.10.4 |
| gnupg | libgcrypt | 1.11.0 ≤ 𝑥 < 1.11.3 |
| gnupg | libgcrypt | 1.12.0 ≤ 𝑥 < 1.12.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| libgcrypt |
| ||
| libgcrypt-debuginfo |
| ||
| libgcrypt-debugsource |
| ||
| libgcrypt-devel |
| ||
| libgcrypt-devel-debuginfo |
|
Common Weakness Enumeration
Vulnerability Media Exposure