CVE-2026-24883Disclosure(gnupg / gnupg)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnupg gnupg systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gnupg
  • gpg4win

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-01-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
gnupggpg4win

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-28: 1Mentions · 2026-02-08: 1Patch / Workaround · 2026-02-08: 1Technical Details · 2026-01-27: 2Technical Details · 2026-02-08: 101-2701-2802-08
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-01-281
Disclosure1
2026-02-081
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    GnuPG 2.5.17 fixes possible RCE & more https://www.openwall.com/lists/oss-security/2026/01/27/8 CVE-2026-24881 T8044 gpg-agent stack buffer overflow in pkdecrypt using KEM, affects only GnuPG and Gpg4win released 2025-10-22+ CVE-2026-24882 T8045 Stack-based buffer overflow in TPM2 PKDECRYPT CVE-2026-24883 T8049

    Post summary

    GnuPG 2.5.17 addresses several CVEs involving stack buffer overflows, providing a fix; no PoC, exploit code, or active exploitation is reported.

    0321041.3K
    4.4K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 GnuPGの脆弱性(High: CVE-2026-24881, CVE-2026-24882, Low: CVE-2026-24883) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #gnupg #gpg https://security.sios.jp/vulnerability/gnupg-security-vulnerability-20260129/

    Post summary

    The post announces three new GnuPG vulnerabilities with their CVE IDs and severity ratings, directing readers to a blog for further information.

    00010117
    360 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24883 GnuPG Signature Packet Length Vulnerability Causing Denial of Service Before 2.5.17 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24883

    Post summary

    A new GnuPG signature packet length vulnerability (CVE‑2026‑24883) that triggers denial of service in versions before 2.5.17 has been disclosed, but no PoC, exploit, active misuse, patch, or debunking information is provided.

    0000065
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24883 In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (… https://www.cve.org/CVERecord?id=CVE-2026-24883

    Post summary

    GnuPG before version 2.5.17 has a denial‑of‑service vulnerability triggered by long signature packets, as detailed in CVE‑2026‑24883.

    00000268
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgnupggnupg---
Appgpg4wingpg4win---

Explore more