CVE-2025-68973: In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:P
Exploit Status
Not Exploited
Patch Tuesday
2025-Dec
Released
2025-12-30
Last Updated
2026-02-25
EPSS Score
0.02% (percentile: 4.7%)

Affected Products (2)

Other

  • 20333-17084
  • 20331-17086

Revision History

  • 2025-12-30: Information published.
  • 2026-01-03: Information published.
  • 2026-01-06: Information published.
  • 2026-02-25: Information published.