CVE-2026-41989
published 2026-04-23CVE-2026-41989: Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
PriorityP429medium6.7CVSS 3.1
AVLACHPRNUINSUCNIHAH
EPSS
0.18%
8.0th percentile
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | >= 1.11.0 < 1.11.3 | 1.11.3 |
| gnupg | libgcrypt | >= 1.12.0 < 1.12.2 | 1.12.2 |
| gnupg | libgcrypt | >= 1.8.8 < 1.10.4 | 1.10.4 |
| mozilla | thunderbird | — | — |
| ubuntu | libgcrypt20 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
vendor_redhat6.7MEDIUM
vendor_ubuntu6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2026-05-27·CVSS 6.7
CVE-2026-41989 [MEDIUM] Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Several security issues were fixed in Libgcrypt.
It was discovered that Libgcrypt incorrectly handled crafted ECDH
ciphertext. An attacker could possibly use this issue to cause Libgcrypt to
crash, resulting in a denial of service. (CVE-2026-41989)
It was discovered that Libgcrypt incorrectly handled Dilithium signing. An
attacker could possibly use this issue to cause Libgcrypt to crash,
resulting in a denial of service. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-41990)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
vendor_redhat·2026-04-23·CVSS 6.7
CVE-2026-41989 [MEDIUM] CWE-131 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: libgcrypt (Red Hat Enterprise Linux 10) - Affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Affected
Package: libgcrypt (Red Hat Enterprise Linux 6) -
GHSA
GHSA-wrv8-79m2-qg24: Libgcrypt before 1
ghsa_unreviewed·2026-04-23
CVE-2026-41989 [MEDIUM] CWE-787 GHSA-wrv8-79m2-qg24: Libgcrypt before 1
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [epel-all]
bugzilla·2026-04-25·CVSS 6.7
CVE-2026-41989 [MEDIUM] CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [epel-all]
CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41989 libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
bugzilla·2026-04-25·CVSS 6.7
CVE-2026-41989 [MEDIUM] CVE-2026-41989 libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
CVE-2026-41989 libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
bugzilla·2026-04-25·CVSS 6.7
CVE-2026-41989 [MEDIUM] CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
CVE-2026-41989 mingw-libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41989 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
bugzilla·2026-04-23·CVSS 6.7
CVE-2026-41989 [MEDIUM] CVE-2026-41989 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
CVE-2026-41989 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
2026-04-23
Published