Logo
vulnerabilityCVE-2026-57062
Name
CVE-2026-57062
Source
NVD ( link)Debian ( link)
Description
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
gnupg
Exploitable

Vulnerability Ratings#


2.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.4.23
Exploitable
buildroot
2025.02.x
2.4.9
Exploitable
buildroot
master
1.4.23
Exploitable
buildroot
master
2.5.21
Not Affected
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
openwrt
openwrt-25.12
2.4.8-r1
Exploitable
yocto
kirkstone
2.3.7
Exploitable
yocto
master
2.5.21
Not Affected
yocto
scarthgap
2.4.9
Exploitable