Logo
vulnerabilityCVE-2025-68973
Name
CVE-2025-68973
Source
NVD ( link)Debian ( link)
Description
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gnupg
Exploitable
gnupg2
Exploitable

Vulnerability Ratings#


7.8
CVSSv31
7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.4.23
Exploitable
buildroot
2025.02.x
2.4.9
Not Affected
buildroot
master
1.4.23
Exploitable
buildroot
master
2.5.20
Not Affected
openwrt
master
1.4.23-r5
Exploitable
openwrt
master
2.5.20-r1
Not Affected
yocto
kirkstone
2.3.7
Patched
yocto
master
2.5.17
Not Affected
yocto
scarthgap
2.4.9
Not Affected

Resolved with patches#


gnupg (yocto:kirkstone)

#
Title
Author
Resolve
1
gpg: Fix possible memory corruption in the armor parser.
Werner Koch <wk@gnupg.org>
CVE-2025-68973