CVE-2026-41989: Buffer Overflow
Last updated 27 May 2026
Other sources
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcrypkdecrypt.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libgcrypt20to a version that resolves this vulnerability.Fixed in 1.8.7-6Fixed in 1.10.1-3+deb12u1Fixed in 1.11.0-7+deb13u1Fixed in 1.12.2-1 - Upgrade
Upgrade
libgcryptto a version that resolves this vulnerability.Fixed in 1.12.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41989?
CVE-2026-41989 has a high severity due to the potential for heap-based buffer overflow and denial of service.
How do I fix CVE-2026-41989?
To fix CVE-2026-41989, update libgcrypt to version 1.12.2 or later.
What software is affected by CVE-2026-41989?
CVE-2026-41989 affects libgcrypt versions prior to 1.12.2.
What might be the impact of CVE-2026-41989?
The impact of CVE-2026-41989 includes potential denial of service and security compromise through crafted ECDH ciphertext.
Is CVE-2026-41989 remotely exploitable?
Yes, CVE-2026-41989 is remotely exploitable if an attacker can send crafted ECDH ciphertext to the vulnerable software.