Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <aVIaYxlz7Am8NcgF@eldamar.lan>
Date: Mon, 29 Dec 2025 07:06:27 +0100
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Cc: Solar Designer <solar@...nwall.com>, contact@....fail
Subject: Re: Many vulnerabilities in GnuPG

Hi,

FTR, these two got CVE assignments so far:

On Sun, Dec 28, 2025 at 12:47:30AM -0600, Jacob Bachmeyer wrote:
[...]
> Item 3: Cleartext Signature Plaintext Truncated for Hash Calculation
https://gpg.fail/formfeed

https://www.cve.org/CVERecord?id=CVE-2025-68972

> Item 5: Memory Corruption in ASCII-Armor Parsing
https://gpg.fail/memcpy

https://www.cve.org/CVERecord?id=CVE-2025-68973

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.