Follow @Openwall on Twitter for new release announcements and other news
[<prev] [day] [month] [year] [list]
Message-ID: <87bja2f093.fsf@gentoo.org>
Date: Sun, 13 Sep 2026 01:44:40 +0100
From: Sam James <sam@...too.org>
To: oss-security@...ts.openwall.com
Cc: Lexi Groves (49016) <contact@....fail>, Werner Koch <wk@...pg.org>
Subject: Retrospective by 'gpg.fail' authors

Hi,

The authors of the 'gpg.fail' set of vulnerabilities have published a
retrospective, previously discussed on this list [0].

A recording of the talk is available [1] as are slides [2].

They also mention another vulnerability in the slides that is in the
talk but I've not seen that yet. A PoC is available in their repo [3].

(I've only made my way through the slides on an initial first pass, so I
don't consider myself in a position to comment on the contents at this
time.)

[0] https://www.openwall.com/lists/oss-security/2025/12/28/1
[1] https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026
[2] https://git.gay/49016/gpg-fail-aftermath/raw/branch/main/slides.pd
[3] https://git.gay/49016/gpg-fail-aftermath/src/branch/main/pocs

sam

Download attachment "signature.asc" of type "application/pgp-signature" (419 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.