Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 11 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0197.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-68973, CVE-2026-24882, CVE-2026-24883 Description: CVE-2025-68973, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. CVE-2026-24882, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys. CVE-2026-24883, a long signature packet length causes parse_signature to return success with sig-> data[] set to a NULL value, leading to a denial of service (application crash). Upstream has still not fixed CVE-2025-68972. We will be tracking the solution and providing an update to fix it when possible. References: - https://bugs.mageia.org/show_bug.cgi?id=34934 - https://www.openwall.com/lists/oss-security/2025/12/28/1 - https://ubuntu.com/security/notices/USN-7946-1 - https://www.openwall.com/lists/oss-security/2026/01/27/8 - https://www.openwall.com/lists/oss-security/2026/01/27/11 - https://www.cve.org/CVERecord?id=CVE-2025-68973 - https://www.cve.org/CVERecord?id=CVE-2026-24882 - https://www.cve.org/CVERecord?id=CVE-2026-24883 SRPMS: - 9/core/gnupg2-2.3.8-1.5.mga9 . Critical Mageia security advisory for gnupg2 reveals important fixes for multiple vulnerabilities.. Mageia Security Update, gnupg2 Buffer Overflow, Mageia 9 Threats. . Severity: Important. LinuxSecurity.com Team
Important: gnupg2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2719", "synopsis": "Important: gnupg2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for gnupg2.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.\n\nSecurity Fix(es):\n\n* GnuPG: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution (CVE-2026-24882)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2433464", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2433464", "description": ""}], "cves": [{"name": "CVE-2026-24882", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-24882", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.4", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-02-24T18:56:34.668877Z", "rpms": {"Rocky Linux 10": {"nvras": ["gnupg2-0:2.4.5-4.el10_1.src.rpm", "gnupg2-smime-0:2.4.5-4.el10_1.aarch64.rpm", "gnupg2-debugsource-0:2.4.5-4.el10_1.ppc64le.rpm", "gnupg2-debuginfo-0:2.4.5-4.el10_1.x86_64.rpm", "gnupg2-debuginfo-0:2.4.5-4.el10_1.s390x.rpm", "gnupg2-0:2.4.5-4.el10_1.x86_64.rpm", "gnupg2-smime-debuginfo-0:2.4.5-4.el10_1.x86_64.rpm", "gnupg2-debugsource-0:2.4.5-4.el10_1.s390x.rpm", "gnupg2-debuginfo-0:2.4.5-4.el10_1.aarch64.rpm", "gnupg2-0:2.4.5-4.el10_1.ppc64le.rpm", "gnupg2-smime-0:2.4.5-4.el10_1.x86_64.rpm", "gnupg2-smime-debuginfo-0:2.4.5-4.el10_1.s390x.rpm", "gnupg2-0:2.4.5-4.el10_1.aarch64.rpm","gnupg2-smime-debuginfo-0:2.4.5-4.el10_1.aarch64.rpm", "gnupg2-smime-0:2.4.5-4.el10_1.s390x.rpm", "gnupg2-0:2.4.5-4.el10_1.s390x.rpm", "gnupg2-smime-0:2.4.5-4.el10_1.ppc64le.rpm", "gnupg2-debugsource-0:2.4.5-4.el10_1.aarch64.rpm", "gnupg2-smime-debuginfo-0:2.4.5-4.el10_1.ppc64le.rpm", "gnupg2-debugsource-0:2.4.5-4.el10_1.x86_64.rpm", "gnupg2-debuginfo-0:2.4.5-4.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security update for gnupg2 on Rocky Linux addresses a buffer overflow which may lead to code execution risks.. gnupg2 security update, Rocky Linux update, Important security advisory, buffer overflow fix, remote code execution fix. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-1677 http://linux.oracle.com/errata/ELSA-2026-1677.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: gnupg2-2.0.22-5.0.1.el7_5.x86_64.rpm gnupg2-smime-2.0.22-5.0.1.el7_5.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/gnupg2-2.0.22-5.0.1.el7_5.src.rpm Related CVEs: CVE-2025-68973 Description of changes: [2.0.22-5.0.1] - Fix CVE-2025-68973 (gpg.fail/memcpy) [Orabug: 38914175] _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2719 http://linux.oracle.com/errata/ELSA-2026-2719.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: gnupg2-2.4.5-4.el10_1.x86_64.rpm gnupg2-smime-2.4.5-4.el10_1.x86_64.rpm aarch64: gnupg2-2.4.5-4.el10_1.aarch64.rpm gnupg2-smime-2.4.5-4.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/gnupg2-2.4.5-4.el10_1.src.rpm Related CVEs: CVE-2026-24882 Description of changes: [2.4.5-4] - Fix CVE-2026-24882 (tpm2daemon buffer overflow) _______________________________________________ El-errata mailing list
Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-59fdfa64f5 2026-02-17 01:16:30.424623+00:00 -------------------------------------------------------------------------------- Name : gnupg2 Product : Fedora 42 Version : 2.4.9 Release : 2.fc42 URL : https://www.gnupg.org/ Summary : Utility for secure communication and data storage Description : GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440 and the S/MIME standard as described by several RFCs. GnuPG 2.0 is a newer version of GnuPG with additional support for S/MIME. It has a different design philosophy that splits functionality up into several modules. The S/MIME and smartcard functionality is provided by the gnupg2-smime package. -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 3 2026 Jakub Jelen - 2.4.9-2 - Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution -------------------------------------------------------------------------------- References: [ 1 ] Bug #2433663 - CVE-2026-24882 gnupg2: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2433663 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-59fdfa64f5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d5c00a447f 2026-02-05 00:57:20.049144+00:00 -------------------------------------------------------------------------------- Name : gnupg2 Product : Fedora 43 Version : 2.4.9 Release : 5.fc43 URL : https://www.gnupg.org/ Summary : Utility for secure communication and data storage Description : GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440 and the S/MIME standard as described by several RFCs. GnuPG 2.0 is a newer version of GnuPG with additional support for S/MIME. It has a different design philosophy that splits functionality up into several modules. The S/MIME and smartcard functionality is provided by the gnupg2-smime package. -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 28 2026 Jakub Jelen - 2.4.9-5 - Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution -------------------------------------------------------------------------------- References: [ 1 ] Bug #2433665 - CVE-2026-24882 gnupg2: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2433665 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-d5c00a447f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: gnupg2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0719", "synopsis": "Important: gnupg2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for gnupg2.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.\n\nSecurity Fix(es):\n\n* GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write (CVE-2025-68973)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2425966", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2425966", "description": ""}], "cves": [{"name": "CVE-2025-68973", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68973", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N", "cvss3BaseScore": "7.8", "cwe": "CWE-675"}], "references": [], "publishedAt": "2026-01-20T09:05:33.258641Z", "rpms": {"Rocky Linux 9": {"nvras": ["gnupg2-smime-debuginfo-0:2.3.3-5.el9_7.ppc64le.rpm", "gnupg2-0:2.3.3-5.el9_7.aarch64.rpm", "gnupg2-0:2.3.3-5.el9_7.ppc64le.rpm", "gnupg2-0:2.3.3-5.el9_7.s390x.rpm", "gnupg2-0:2.3.3-5.el9_7.src.rpm", "gnupg2-0:2.3.3-5.el9_7.x86_64.rpm", "gnupg2-debuginfo-0:2.3.3-5.el9_7.aarch64.rpm", "gnupg2-debuginfo-0:2.3.3-5.el9_7.ppc64le.rpm", "gnupg2-debuginfo-0:2.3.3-5.el9_7.s390x.rpm", "gnupg2-debuginfo-0:2.3.3-5.el9_7.x86_64.rpm", "gnupg2-debugsource-0:2.3.3-5.el9_7.aarch64.rpm", "gnupg2-debugsource-0:2.3.3-5.el9_7.ppc64le.rpm", "gnupg2-debugsource-0:2.3.3-5.el9_7.s390x.rpm","gnupg2-debugsource-0:2.3.3-5.el9_7.x86_64.rpm", "gnupg2-smime-0:2.3.3-5.el9_7.aarch64.rpm", "gnupg2-smime-0:2.3.3-5.el9_7.ppc64le.rpm", "gnupg2-smime-0:2.3.3-5.el9_7.s390x.rpm", "gnupg2-smime-0:2.3.3-5.el9_7.x86_64.rpm", "gnupg2-smime-debuginfo-0:2.3.3-5.el9_7.aarch64.rpm", "gnupg2-smime-debuginfo-0:2.3.3-5.el9_7.s390x.rpm", "gnupg2-smime-debuginfo-0:2.3.3-5.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important gnupg2 security update addresses potential risks such as information disclosure and arbitrary code execution in Rocky Linux 9.. Rocky Linux, gnupg2, security update, information disclosure, code execution. . Severity: Important. LinuxSecurity.com Team
Important: gnupg2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0697", "synopsis": "Important: gnupg2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for gnupg2.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.\n\nSecurity Fix(es):\n\n* GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write (CVE-2025-68973)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2425966", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2425966", "description": ""}], "cves": [{"name": "CVE-2025-68973", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68973", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N", "cvss3BaseScore": "7.8", "cwe": "CWE-675"}], "references": [], "publishedAt": "2026-01-17T09:07:37.776055Z", "rpms": {"Rocky Linux 10": {"nvras": ["gnupg2-smime-debuginfo-0:2.4.5-3.el10_1.ppc64le.rpm", "gnupg2-0:2.4.5-3.el10_1.src.rpm", "gnupg2-0:2.4.5-3.el10_1.x86_64.rpm", "gnupg2-smime-debuginfo-0:2.4.5-3.el10_1.x86_64.rpm", "gnupg2-debugsource-0:2.4.5-3.el10_1.aarch64.rpm", "gnupg2-debugsource-0:2.4.5-3.el10_1.ppc64le.rpm", "gnupg2-debuginfo-0:2.4.5-3.el10_1.ppc64le.rpm", "gnupg2-0:2.4.5-3.el10_1.s390x.rpm", "gnupg2-smime-debuginfo-0:2.4.5-3.el10_1.aarch64.rpm", "gnupg2-smime-0:2.4.5-3.el10_1.x86_64.rpm", "gnupg2-smime-0:2.4.5-3.el10_1.aarch64.rpm", "gnupg2-debuginfo-0:2.4.5-3.el10_1.x86_64.rpm","gnupg2-smime-debuginfo-0:2.4.5-3.el10_1.s390x.rpm", "gnupg2-smime-0:2.4.5-3.el10_1.s390x.rpm", "gnupg2-debuginfo-0:2.4.5-3.el10_1.aarch64.rpm", "gnupg2-smime-0:2.4.5-3.el10_1.ppc64le.rpm", "gnupg2-debugsource-0:2.4.5-3.el10_1.x86_64.rpm", "gnupg2-0:2.4.5-3.el10_1.aarch64.rpm", "gnupg2-debugsource-0:2.4.5-3.el10_1.s390x.rpm", "gnupg2-debuginfo-0:2.4.5-3.el10_1.s390x.rpm", "gnupg2-0:2.4.5-3.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. GnuPG update available for Rocky Linux 10 with important fixes for information disclosure and code execution risks.. gnupg2 update, Rocky Linux, security risks, information disclosure. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.