openwrt ▾
›
openwrt-25.12 ▾
›
component
›
libgcrypt
Component Overview
Vulnerability Overview
Name
libgcrypt
Version
1.11.1-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:gnupg:libgcrypt:1.11.1:*:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
openwrt
master
1.12.2-r1
Vulnerabilities
#
Name
Analysis
Description
CVE-2026-41989
Exploitable
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
CVE-2024-2236
Exploitable
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.