Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-30258

Published: March 21, 2025Last modified: June 18, 2025

Description

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

Severity score breakdown

ParameterValue
Base score2.7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgnupgUnknown (2.2.40-r0)
StreamgnupgUnknown (2.4.0-r1)

References

ON THIS PAGE