CVE-2026-41990
published 2026-04-23CVE-2026-41990: Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
PriorityP416medium4CVSS 3.1
AVLACHPRNUINSUCNILAL
EPSS
0.18%
7.3th percentile
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | >= 1.12.0 < 1.12.2 | 1.12.2 |
| mozilla | thunderbird | — | — |
| ubuntu | libgcrypt20 | — | — |
CVSS provenance
nvdv3.14.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
vendor_ubuntu6.7MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78pv-qq8x-94px: Libgcrypt before 1
ghsa_unreviewed·2026-04-23
CVE-2026-41990 [MEDIUM] CWE-787 GHSA-78pv-qq8x-94px: Libgcrypt before 1
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
Ubuntu
Libgcrypt vulnerabilities
vendor_ubuntu·2026-05-27·CVSS 6.7
CVE-2026-41989 [MEDIUM] Libgcrypt vulnerabilities
Title: Libgcrypt vulnerabilities
Summary: Several security issues were fixed in Libgcrypt.
It was discovered that Libgcrypt incorrectly handled crafted ECDH
ciphertext. An attacker could possibly use this issue to cause Libgcrypt to
crash, resulting in a denial of service. (CVE-2026-41989)
It was discovered that Libgcrypt incorrectly handled Dilithium signing. An
attacker could possibly use this issue to cause Libgcrypt to crash,
resulting in a denial of service. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-41990)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing.
vendor_redhat·2026-04-23·CVSS 4.0
CVE-2026-41990 [MEDIUM] CWE-787 Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing.
Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing.
A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: libgcrypt (Red Hat Enterprise Linux 10) - Fix deferred
Package: thunderbird (Red
No detection rules found.
No public exploits indexed.
2026-04-23
Published