PT-2026-34640 · Libgcrypt+3 · Libgcrypt+3

CVE-2026-41989

·

Published

2026-04-07

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Libgcrypt versions prior to 1.12.2
Description A heap-based buffer overflow and denial of service can occur when processing crafted ECDH ciphertext through the gcry pk decrypt() function.
Recommendations Update to version 1.12.2 or later.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47117
ALSA-2026:50144
ALSA-2026:50147
AZL-83544
BDU:2026-07879
CVE-2026-41989
ECHO-AFBA-F32F-E1D7
JLSEC-2026-496
OESA-2026-2345
OESA-2026-2346
OESA-2026-2347
OESA-2026-2348
OPENSUSE-SU-2026:21387-1
RHSA-2026:47117
RHSA-2026:50144
RHSA-2026:50147
RHSA-2026:52950
RHSA-2026:52951
RHSA-2026:52952
RHSA-2026:52953
RHSA-2026:58977
RHSA-2026:58978
RHSA-2026:58979
RHSA-2026:8466
SUSE-SU-2026:22760-1
SUSE-SU-2026:22826-1
SUSE-SU-2026:22907-1
SUSE-SU-2026:22919-1
SUSE-SU-2026:3182-1
SUSE-SU-2026:3491-1
SUSE-SU-2026:3921-1
USN-8319-1

Affected Products

Libgcrypt
Linuxmint
Rocky Linux
Ubuntu