cbcvebase.
CVE-2026-41990
published 2026-04-23

CVE-2026-41990: Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

medium4CVSS 3.1
AVLACHPRNUINSUCNILAL
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

Affected

4 ranges
VendorProductVersion rangeFixed in
gnupglibgcrypt
gnupglibgcrypt>= 1.12.0 < 1.12.21.12.2
mozillathunderbird
ubuntulibgcrypt20