CVE-2025-68973
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-675
- Published
- 2025-12-28
- Last modified
- 2026-04-30
Affected products
- GnuPG GnuPG
- GnuPG GnuPG
Weakness type
Related vulnerabilities
- CVE-2019-17638 — In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response...