CVE-2025-68973: High severity gnupg GnuPG vulnerability
In GnuPG before 2.4.9, armorfilter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
Other sources
In GnuPG through 2.4.8, armorfilter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GnuPGto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
GnuPG (ExtendedLTS)to a version that resolves this vulnerability.Fixed in 2.2.51
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68973?
CVE-2025-68973 is considered a high-severity vulnerability due to its potential for out-of-bounds writes, which could lead to arbitrary code execution.
How do I fix CVE-2025-68973?
To fix CVE-2025-68973, upgrade GnuPG to version 2.4.9 or later, which addresses this vulnerability.
What impact does CVE-2025-68973 have on GnuPG users?
CVE-2025-68973 may allow attackers to exploit crafted inputs and potentially execute arbitrary code on vulnerable systems.
Is CVE-2025-68973 publicly known?
Yes, CVE-2025-68973 was publicly disclosed and is known within the cybersecurity community.
Which versions of GnuPG are affected by CVE-2025-68973?
GnuPG versions up to and including 2.4.8 are affected by CVE-2025-68973.