
GnuPG 2.5.17 fixes possible RCE & more https://www.openwall.com/lists/oss-security/2026/01/27/8 CVE-2026-24881 T8044 gpg-agent stack buffer overflow in pkdecrypt using KEM, affects only GnuPG and Gpg4win released 2025-10-22+ CVE-2026-24882 T8045 Stack-based buffer overflow in TPM2 PKDECRYPT CVE-2026-24883 T8049
Post summary
GnuPG 2.5.17 addresses several CVEs involving stack buffer overflows, providing a fix; no PoC, exploit code, or active exploitation is reported.



