buildroot ▾
›
master ▾
›
vulnerability
›
CVE-2025-68973
Component Overview
Vulnerability Overview
Name
CVE-2025-68973
Source
NVD (
link
)
Debian (
link
)
Description
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
CWEs
CWE-675
CWE-787
Published Date
Dec 28, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c#L1305-L1306
Product
https://github.com/gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9
Patch
https://github.com/gpg/gnupg/compare/gnupg-2.2.50...gnupg-2.2.51
Patch
https://gpg.fail/memcpy
Broken Link
https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i
Issue Tracking
https://news.ycombinator.com/item?id=46403200
Issue Tracking
https://www.openwall.com/lists/oss-security/2025/12/28/5
Mailing List
http://www.openwall.com/lists/oss-security/2025/12/29/11
Mailing List
https://gpg.fail/memcpy
Broken Link
Analysis
#
Affected Component
Analysis
gnupg
Exploitable
Vulnerability Ratings
#
7.8
CVSSv31
7
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Exploitable
gnupg2
buildroot
2025.02.x
2.4.9
Not Affected
gnupg
openwrt
master
1.4.23-r5
Exploitable
gnupg2
openwrt
master
2.5.20-r1
Not Affected
gnupg
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
gnupg2
openwrt
openwrt-25.12
2.4.8-r1
Exploitable
gnupg
yocto
kirkstone
2.3.7
Patched
gnupg
yocto
master
2.5.17
Not Affected
gnupg
yocto
scarthgap
2.4.9
Not Affected
Resolved with patches
#
gnupg (yocto:kirkstone)
#
Title
Author
Resolve
1
gpg: Fix possible memory corruption in the armor parser.
Werner Koch <wk@gnupg.org>
CVE-2025-68973