yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-24882
Component Overview
Vulnerability Overview
Name
CVE-2026-24882
Source
NVD (
link
)
Debian (
link
)
Description
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
CWEs
CWE-121
Published Date
Jan 27, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://dev.gnupg.org/T8045
Exploit
https://www.openwall.com/lists/oss-security/2026/01/27/8
Mailing List
Analysis
#
Affected Component
Analysis
gnupg
Patched
Vulnerability Ratings
#
8.4
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Not Affected
gnupg2
buildroot
2025.02.x
2.4.9
Not Affected
gnupg
buildroot
master
1.4.23
Not Affected
gnupg2
buildroot
master
2.5.20
Not Affected
gnupg
openwrt
master
1.4.23-r5
Not Affected
gnupg2
openwrt
master
2.5.20-r1
Not Affected
gnupg
openwrt
openwrt-25.12
1.4.23-r5
Not Affected
gnupg2
openwrt
openwrt-25.12
2.4.8-r1
Not Affected
gnupg
yocto
kirkstone
2.3.7
Not Affected
gnupg
yocto
master
2.5.17
Not Affected
Resolved with patches
#
gnupg (yocto:scarthgap)
#
Title
Author
Resolve
1
agent: Fix the regression in pkdecrypt with TPM RSA.
NIIBE Yutaka <gniibe@fsij.org>
CVE-2026-24882
2
tpm: Fix possible buffer overflow in PKDECRYPT
Werner Koch <wk@gnupg.org>
CVE-2026-24882