CVE-2025-30258
published 2025-03-19CVE-2025-30258: In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags…
PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
8.1th percentile
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnupg2 | < gnupg2 2.2.46-5 (forky) | gnupg2 2.2.46-5 (forky) |
| gnupg | gnupg | < 2.5.5 | 2.5.5 |
| gnupg | gnupg | < 2.4.8 | 2.4.8 |
| gnupg | gnupg | >= 2.5.0 < 2.5.5 | 2.5.5 |
| msrc | azl3_gnupg2_2.4.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnupg2_2.4.9-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnupg2_2.4.9-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnupg2_2.4.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gnupg2_2.4.0-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian2.7LOW
vendor_msrc2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rjg-pf4q-hgcr: In GnuPG before 2
ghsa_unreviewed·2025-03-19
CVE-2025-30258 [LOW] CWE-754 GHSA-5rjg-pf4q-hgcr: In GnuPG before 2
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
OSV
CVE-2025-30258: In GnuPG before 2
osv·2025-03-19·CVSS 4.7
CVE-2025-30258 [MEDIUM] CVE-2025-30258: In GnuPG before 2
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2025-12-09
CVE-2025-30258 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to corrupt a keyring.
USN-7412-1 fixed a vulnerability in GnuPG. This update provides the
corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that GnuPG incorrectly handled importing keys with
certain crafted subkey data. If a user or automated system were tricked
into importing a specially crafted key, a remote attacker may prevent
users from importing other keys in the future.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2025-04-03
CVE-2025-30258 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to corrupt a keyring.
It was discovered that GnuPG incorrectly handled importing keys with
certain crafted subkey data. If a user or automated system were tricked
into importing a specially crafted key, a remote attacker may prevent users
from importing other keys in the future.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnupg: verification DoS due to a malicious subkey in the keyring
vendor_redhat·2025-03-19·CVSS 2.7
CVE-2025-30258 [LOW] CWE-754 gnupg: verification DoS due to a malicious subkey in the keyring
gnupg: verification DoS due to a malicious subkey in the keyring
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.
Statement: This vulnerability is rated as LOW impact. This is because it exists in GnuPG's certificate import logic. When a user imports a craf
Microsoft
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify sig
vendor_msrc·2025-03-11·CVSS 2.7
CVE-2025-30258 [LOW] CWE-754 In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify sig
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informat
Debian
CVE-2025-30258: gnupg2 - In GnuPG before 2.5.5, if a user chooses to import a certificate with certain cr...
vendor_debian·2025·CVSS 2.7
CVE-2025-30258 [LOW] CVE-2025-30258: gnupg2 - In GnuPG before 2.5.5, if a user chooses to import a certificate with certain cr...
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.2.46-5)
sid: resolved (fixed in 2.2.46-5)
trixie: resolved (fixed in 2.2.46-5)
No detection rules found.
No public exploits indexed.
2025-03-19
Published