Home / mailingsPDF  

[USN-8720-1] GnuPG vulnerability

Posted on 03 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8720-1
September 03, 2026

gnupg2 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS

Summary:

GnuPG could allow encrypted messages to be forged under certain
circumstances.

Software Description:
- gnupg2: GNU privacy guard - a free PGP replacement

Details:

It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
gpgsm 2.4.8-4ubuntu3.1

Ubuntu 24.04 LTS
gpgsm 2.4.4-2ubuntu17.6

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8720-1
CVE-2026-57062

Package Information:
https://launchpad.net/ubuntu/+source/gnupg2/2.4.8-4ubuntu3.1
https://launchpad.net/ubuntu/+source/gnupg2/2.4.4-2ubuntu17.6

--===============3501557396523495567==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP