openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2025-68973
Component Overview
Vulnerability Overview
Name
CVE-2025-68973
Source
NVD (
link
)
Debian (
link
)
Description
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
CWEs
CWE-675
CWE-787
Published Date
Dec 28, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c#L1305-L1306
Product
https://github.com/gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9
Patch
https://github.com/gpg/gnupg/compare/gnupg-2.2.50...gnupg-2.2.51
Patch
https://gpg.fail/memcpy
Broken Link
https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i
Issue Tracking
https://news.ycombinator.com/item?id=46403200
Issue Tracking
https://www.openwall.com/lists/oss-security/2025/12/28/5
Mailing List
http://www.openwall.com/lists/oss-security/2025/12/29/11
Mailing List
https://gpg.fail/memcpy
Broken Link
Analysis
#
Affected Component
Analysis
gnupg
Exploitable
Vulnerability Ratings
#
7.8
CVSSv31
7
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Exploitable
gnupg2
buildroot
2025.02.x
2.4.9
Not Affected
gnupg
buildroot
master
1.4.23
Exploitable
gnupg2
buildroot
master
2.5.20
Not Affected
gnupg
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
gnupg2
openwrt
openwrt-25.12
2.4.8-r1
Exploitable
gnupg
yocto
kirkstone
2.3.7
Patched
gnupg
yocto
master
2.5.17
Not Affected
gnupg
yocto
scarthgap
2.4.9
Not Affected
Resolved with patches
#
gnupg (yocto:kirkstone)
#
Title
Author
Resolve
1
gpg: Fix possible memory corruption in the armor parser.
Werner Koch <wk@gnupg.org>
CVE-2025-68973