CVE-2026-24882

Published: January 29, 2026Last modified: February 2, 2026

Description

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgnupgVulnerable (2.2.40-r0)
25 LTSgnupgVulnerable (2.4.7-r0)
StreamgnupgVulnerable (2.4.0-r1)

References

ON THIS PAGE