# CVE-2025-68973

## Summary

- **CVE ID:** CVE-2025-68973
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-675
- **Published:** Dec 28, 2025
- **Last Modified:** Apr 30, 2026

## Description

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

## Affected Products

- GnuPG — GnuPG (0)
- GnuPG — GnuPG (2.3.0)

## References

- [CNA](https://gpg.fail/memcpy)
- [CNA](https://news.ycombinator.com/item?id=46403200)
- [CNA](https://www.openwall.com/lists/oss-security/2025/12/28/5)
- [CNA](https://github.com/gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9)
- [CNA](https://github.com/gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c#L1305-L1306)
- [CNA](https://github.com/gpg/gnupg/compare/gnupg-2.2.50...gnupg-2.2.51)
- [CNA](https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i)
- [CVE](http://www.openwall.com/lists/oss-security/2025/12/29/11)
- [CVE](https://lists.debian.org/debian-lts-announce/2026/01/msg00008.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._