cbcvebase.
CVE-2025-68973
published 2025-12-28

CVE-2025-68973: In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted…

PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangnupg2< gnupg2 2.2.40-1.1+deb12u2 (bookworm)gnupg2 2.2.40-1.1+deb12u2 (bookworm)
gnupggnupg< 2.2.512.2.51
gnupggnupg<= 2.4.8
gnupggnupg>= 2.3.0 < 2.4.92.4.9
msrcazl3_gnupg2_2.4.7-1_on_azure_linux_3.0
msrccbl2_gnupg2_2.4.0-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.