USN-7412-2: GnuPG regression
USN-7412-2: GnuPG regression
Publication date: 8 July 2025
Overview: USN-7412-1 introduced a regression in GnuPG.
Packages
- gnupg2 - GNU privacy guard - a free PGP replacement
Details
USN-7412-1 fixed vulnerabilities in GnuPG. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that GnuPG incorrectly handled importing keys with
certain crafted subkey data. If a user or automated system were tricked
into importing a specially crafted key, a remote attacker may prevent
users from importing other keys in the future.
Update instructions
The problem can be corrected by updating your system to the following package versions:
24.10 oracular
- gnupg – 2.4.4-2ubuntu18.3
- gnupg2 – 2.4.4-2ubuntu18.3
- gpg – 2.4.4-2ubuntu18.3