Logo
componentlibgcrypt
Name
libgcrypt
Version
1.11.1
Type
library
Description
-
Licenses
LGPL-2.1+
PURL
-
CPE
cpe:2.3:a:gnupg:libgcrypt:1.11.1:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.12.2

Patches#


#
Title
Author
Resolve
1
configure.ac: add an option to disable tests
Fabrice Fontaine <fontaine.fabrice@gmail.com>
2
cipher:ecc: Fix decoding a point on Montgomery curve.
NIIBE Yutaka <gniibe@fsij.org>
CVE-2026-41989

Vulnerabilities#


Name
Analysis
Description
Patched
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Exploitable
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.