
CVE-2026-41990 Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data. https://www.cve.org/CVERecord?id=CVE-2026-41990
Post summary
The advisory reports that Libgcrypt before 1.12.2 mishandles Dilithium signing with an unchecked write to a static array, though it does not use attacker-controlled data, and no PoC, exploit, or patch is discussed.
