Logo
vulnerabilityCVE-2026-24882
Name
CVE-2026-24882
Source
NVD ( link)Debian ( link)
Description
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gnupg
Patched

Vulnerability Ratings#


8.4
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.4.23
Not Affected
buildroot
2025.02.x
2.4.9
Not Affected
buildroot
master
1.4.23
Not Affected
buildroot
master
2.5.20
Not Affected
openwrt
master
1.4.23-r5
Not Affected
openwrt
master
2.5.20-r1
Not Affected
openwrt
openwrt-25.12
1.4.23-r5
Not Affected
openwrt
openwrt-25.12
2.4.8-r1
Not Affected
yocto
kirkstone
2.3.7
Not Affected
yocto
master
2.5.17
Not Affected

Resolved with patches#


gnupg (yocto:scarthgap)

#
Title
Author
Resolve
1
agent: Fix the regression in pkdecrypt with TPM RSA.
NIIBE Yutaka <gniibe@fsij.org>
CVE-2026-24882
2
tpm: Fix possible buffer overflow in PKDECRYPT
Werner Koch <wk@gnupg.org>
CVE-2026-24882