yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-57062
Component Overview
Vulnerability Overview
Name
CVE-2026-57062
Source
NVD (
link
)
Debian (
link
)
Description
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
CWEs
CWE-1284
Published Date
Jun 23, 2026
Updated Date
Jun 25, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
gnupg
Exploitable
Vulnerability Ratings
#
2.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Exploitable
gnupg2
buildroot
2025.02.x
2.4.9
Exploitable
gnupg
buildroot
master
1.4.23
Exploitable
gnupg2
buildroot
master
2.5.21
Not Affected
gnupg
openwrt
master
1.4.23-r5
Exploitable
gnupg2
openwrt
master
2.5.21-r1
Not Affected
gnupg
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
gnupg2
openwrt
openwrt-25.12
2.4.8-r1
Exploitable
gnupg
yocto
master
2.5.21
Not Affected
gnupg
yocto
scarthgap
2.4.9
Exploitable