openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2026-57062
Component Overview
Vulnerability Overview
Name
CVE-2026-57062
Source
NVD (
link
)
Debian (
link
)
Description
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
CWEs
CWE-1284
Published Date
Jun 23, 2026
Updated Date
Jun 25, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
gnupg
Exploitable
Vulnerability Ratings
#
2.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Exploitable
gnupg2
buildroot
2025.02.x
2.4.9
Exploitable
gnupg
buildroot
master
1.4.23
Exploitable
gnupg2
buildroot
master
2.5.21
Not Affected
gnupg
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
gnupg2
openwrt
openwrt-25.12
2.4.8-r1
Exploitable
gnupg
yocto
kirkstone
2.3.7
Exploitable
gnupg
yocto
master
2.5.21
Not Affected
gnupg
yocto
scarthgap
2.4.9
Exploitable