CVE-2025-68972

Published: December 30, 2025Last modified: January 14, 2026

Description

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

Severity score breakdown

ParameterValue
Base score4.7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgnupgUnknown (2.2.40-r0)
25 LTSgnupgFixed (2.4.9-r0)
StreamgnupgFixed (2.4.9-r0)

References

ON THIS PAGE