PT-2026-51574 · Gnu · Gnupg

CVE-2026-57062

·

Published

2026-06-23

·

Updated

2026-09-03

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 2.5.21
Description CMS (Cryptographic Message Syntax) parsing in gpgsm mishandles the CMS format for AES-GCM. The issue occurs because the aes-ICVlen is accepted as 4 bytes, whereas it is supposed to be 12 bytes.
Recommendations Update to a version later than 2.5.20.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91170
CVE-2026-57062
ECHO-89C6-C3E9-D8D2
JLSEC-2026-1084
OESA-2026-2858
OESA-2026-2859
OESA-2026-2860
OPENSUSE-SU-2026:11213-1
OPENSUSE-SU-2026:21385-1
SUSE-SU-2026:22757-1
SUSE-SU-2026:22825-1
SUSE-SU-2026:22923-1
SUSE-SU-2026:23007-1
SUSE-SU-2026:3243-1
USN-8720-1

Affected Products

Gnupg