HarborGuard / CVE
Back to search
HIGHCVE-2026-24882Published Modified CNA mitre

CVE-2026-24882: In GnuPG before 2

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

Metrics

CVSS v3.1
8.4
Severity
HIGH
Fixed in
2.5.17
Affected Products
1

Fix available

2.5.17
Affected packages
  • GnuPG / GnuPG
    < 2.5.17 (from 0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H