RNP is a set of OpenPGP (RFC4880) tools.
Update Information:
Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13470, CVE-2025-13402)
* Fri Nov 21 2025 Remi Collet
[ 1 ] Bug #2415869 - CVE-2025-13402 rnp: RNP PKESK Session Keys Generated as All\u2011Zero [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2415869
[ 2 ] Bug #2417034 - CVE-2025-13470 rnp: RNP: Confidentiality compromise due to uninitialized symmetric session key in Public-Key Encrypted Session Key (PKESK) packets [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2417034
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7bef956026' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.