CVE-2026-41990
EUVD-2026-2519323.04.2026, 05:16
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| gnupg | libgcrypt | 1.12.0 ≤ 𝑥 < 1.12.2 | CNA |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration