Name
CVE-2025-68973
Description
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
Published Date
Updated Date
Workaround
-
Advisories
Analysis#
Vulnerability Ratings#
7.8
CVSSv31
7
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.4.23
Exploitable
buildroot
2025.02.x
2.4.9
Not Affected
buildroot
master
1.4.23
Exploitable
buildroot
master
2.5.20
Not Affected
openwrt
master
1.4.23-r5
Exploitable
openwrt
master
2.5.20-r1
Not Affected
yocto
kirkstone
2.3.7
Patched
yocto
master
2.5.17
Not Affected
yocto
scarthgap
2.4.9
Not Affected
Resolved with patches#
gnupg (yocto:kirkstone)
#
Title
Author
Resolve
1
gpg: Fix possible memory corruption in the armor parser.
Werner Koch <wk@gnupg.org>
CVE-2025-68973