Alerts This Week
Warning Icon 1 1,146
Alerts This Week
Warning Icon 1 1,146

SUSE gpg2 Critical Security Patch Available for CVE-2025-68973 Issue

suse
Calendar Grey January 22, 2026
Dist Suse Esm H88
SUSE gpg2 important fix for memory corruption with security updates available. Install updates to safeguard your systems.
An update that solves one vulnerability and has four security fixes can now be installed.

Summary

## This update for gpg2 fixes the following issues: * CVE-2025-68973: Fix possible memory corruption in the armor parser (gpg.fail/memcpy)(bsc#1255715). * Avoid potential downgrade to SHA1 in 3rd party key signatures (gpg.fail/sha1) (bsc#1256246). * Error out on unverified output for non-detached signatures (gpg.fail/detached) (bsc#1256244). * Fix a memory leak in gpg2 agent (bsc#1256243). * Fix Cleartext Signature Forgery in the NotDashEscaped header implementation in GnuPG (gpg.fail/notdash) (bsc#1256390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-215=1 openSUSE-SLE-15.6-2026-215=1

References

* bsc#1255715

* bsc#1256243

* bsc#1256244

* bsc#1256246

* bsc#1256390

Cross-

* CVE-2025-68973

CVSS scores:

* CVE-2025-68973 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

* CVE-2025-68973 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

* CVE-2025-68973 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server 15 SP6 LTSS

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability and has four security fixes can now be

installed.

##

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0215-1
Release Date: 2026-01-22T12:10:29Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here