Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
# Security update for gpg2 Announcement ID: SUSE-SU-2026:0694-1 Release Date: 2026-02-27T15:14:46Z Rating: moderate References:. # Security update for gpg2 Announcement ID: SUSE-SU-2026:0694-1 Release Date: 2026-02-27T15:14:46Z Rating: moderate References: * bsc#1256389 Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that has one security fix can now be installed. ## Description: This update for gpg2 fixes the following issues: Security fix: * Fixed GnuPG accepting Path Separators and Path Traversals in Literal Data (bsc#1256389) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-694=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-694=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-694=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-694=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-694=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-2.2.27-150300.3.19.1 * dirmngr-debuginfo-2.2.27-150300.3.19.1 *dirmngr-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * openSUSE Leap 15.3 (noarch) * gpg2-lang-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256389 . SUSE updates gpg2 to fix Path Traversals and Path Separators issues. Install suggested updates immediately for security.. SUSE update gpg2 moderate Path Traversals security fix. . LinuxSecurity.com Team
An update that has one security fix can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:0694-1 Release Date: 2026-02-27T15:14:46Z Rating: moderate References: * bsc#1256389 Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that has one security fix can now be installed. ## Description: This update for gpg2 fixes the following issues: Security fix: * Fixed GnuPG accepting Path Separators and Path Traversals in Literal Data (bsc#1256389) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-694=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-694=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-694=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-694=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-694=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-694=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-2.2.27-150300.3.19.1 * dirmngr-debuginfo-2.2.27-150300.3.19.1 * dirmngr-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * openSUSE Leap15.3 (noarch) * gpg2-lang-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * gpg2-2.2.27-150300.3.19.1 * gpg2-debugsource-2.2.27-150300.3.19.1 * gpg2-debuginfo-2.2.27-150300.3.19.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1256389 . Update for openSUSE gpg2 fixes moderate security issue related to path traversal, ensuring system integrity.. openSUSE updates gpg2 security path traversal patch. . LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:20487-1 Release Date: 2026-02-17T09:37:09Z Rating: important References: * bsc#1256389 * bsc#1257396 Cross-References: * CVE-2026-24882 CVSS scores: * CVE-2026-24882 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24882 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for gpg2 fixes the following issues: * CVE-2026-24882: stack-based buffer overflow in TPM2 PKDECRYPT for TPM-backed RSA and ECC keys (bsc#1257396). * gpg.fail/filename: GnuPG Accepts Path Separators and Path Traversals in Literal Data "Filename" Field (bsc#1256389). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-407=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * gpg2-2.4.4-slfo.1.1_7.1 * gpg2-debugsource-2.4.4-slfo.1.1_7.1 * gpg2-debuginfo-2.4.4-slfo.1.1_7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24882.html * https://bugzilla.suse.com/show_bug.cgi?id=1256389 * https://bugzilla.suse.com/show_bug.cgi?id=1257396 . Update for gpg2 addresses critical buffer overflow issue on SUSE Linux Micro 6.1, important patch available now.. gpg2 update SUSE Linux security patch important. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:20444-1 Release Date: 2026-02-16T14:21:11Z Rating: important References: * bsc#1256389 * bsc#1257396 Cross-References: * CVE-2026-24882 CVSS scores: * CVE-2026-24882 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24882 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for gpg2 fixes the following issues: * CVE-2026-24882: stack-based buffer overflow in TPM2 PKDECRYPT for TPM-backed RSA and ECC keys (bsc#1257396). * gpg.fail/filename: GnuPG Accepts Path Separators and Path Traversals in Literal Data "Filename" Field (bsc#1256389). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-582=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * gpg2-2.4.4-7.1 * gpg2-debugsource-2.4.4-7.1 * gpg2-debuginfo-2.4.4-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24882.html * https://bugzilla.suse.com/show_bug.cgi?id=1256389 * https://bugzilla.suse.com/show_bug.cgi?id=1257396 . Update for gpg2 on SUSE solves a stack-based overflow issue, enhancing your system's security.. gpg2 security update,SUSE gpg2 patch,stack overflow fix,SUSE Linux Micro 6.0. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has four fixes can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:20356-1 Release Date: 2026-01-14T09:32:14Z Rating: important References: * bsc#1255715 * bsc#1256243 * bsc#1256244 * bsc#1256246 * bsc#1256390 Cross-References: * CVE-2025-68973 CVSS scores: * CVE-2025-68973 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has four fixes can now be installed. ## Description: This update for gpg2 fixes the following issues: * CVE-2025-68973: out-of-bounds write when processing specially crafted input in the armor parser can lead to memory corruption (bsc#1255715). Other security fixes: * gpg: Avoid potential downgrade to SHA1 in 3rd party key signatures (bsc#1256246). * gpg: Error out on unverified output for non-detached signatures (bsc#1256244). * agent: Fix a memory leak (bsc#1256243). * gpg: Deprecate the option --not-dash-escaped (bsc#1256390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-374=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * gpg2-debuginfo-2.4.4-slfo.1.1_6.1 * gpg2-debugsource-2.4.4-slfo.1.1_6.1 * gpg2-2.4.4-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68973.html * https://bugzilla.suse.com/show_bug.cgi?id=1255715 * https://bugzilla.suse.com/show_bug.cgi?id=1256243 * https://bugzilla.suse.com/show_bug.cgi?id=1256244 * https://bugzilla.suse.com/show_bug.cgi?id=1256246 *https://bugzilla.suse.com/show_bug.cgi?id=1256390 . Important update for gpg2 addresses one critical issue and four additional fixes to enhance security on SUSE systems.. gpg2 security patch SUSE important update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has four fixes can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:20243-1 Release Date: 2026-01-14T09:43:09Z Rating: important References: * bsc#1255715 * bsc#1256243 * bsc#1256244 * bsc#1256246 * bsc#1256390 Cross-References: * CVE-2025-68973 CVSS scores: * CVE-2025-68973 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has four fixes can now be installed. ## Description: This update for gpg2 fixes the following issues: * CVE-2025-68973: out-of-bounds write when processing specially crafted input in the armor parser can lead to memory corruption (bsc#1255715). Other security fixes: * gpg: Avoid potential downgrade to SHA1 in 3rd party key signatures (bsc#1256246). * gpg: Error out on unverified output for non-detached signatures (bsc#1256244). * agent: Fix a memory leak (bsc#1256243). * gpg: Deprecate the option --not-dash-escaped (bsc#1256390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-560=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 ppc64le s390x x86_64) * gpg2-2.4.4-6.1 * gpg2-debugsource-2.4.4-6.1 * gpg2-debuginfo-2.4.4-6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68973.html * https://bugzilla.suse.com/show_bug.cgi?id=1255715 * https://bugzilla.suse.com/show_bug.cgi?id=1256243 * https://bugzilla.suse.com/show_bug.cgi?id=1256244 * https://bugzilla.suse.com/show_bug.cgi?id=1256246 *https://bugzilla.suse.com/show_bug.cgi?id=1256390 . SUSE security update for gpg2 fixes critical memory corruption issue with important severity, fully detailed in advisory.. SUSE Update gpg2 Memory Corruption CVE-2025-68973 Critical Fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:0434-1 Release Date: 2026-02-11T09:23:35Z Rating: important References: * bsc#1256389 * bsc#1257396 Cross-References: * CVE-2026-24882 CVSS scores: * CVE-2026-24882 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-24882 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24882 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for gpg2 fixes the following issues: Security fixes: * CVE-2026-24882: Fixed stack-based buffer overflow in TPM2 PKDECRYPT for TPM- backed RSA and ECC keys (bsc#1257396) * Fixed GnuPG accepting Path Separators and Path Traversals in Literal Data "Filename" Field (bsc#1256389) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-434=1 openSUSE-SLE-15.6-2026-434=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-434=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-434=1 * SUSE Linux Enterprise Server for SAPApplications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-434=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * dirmngr-2.4.4-150600.3.15.1 * gpg2-2.4.4-150600.3.15.1 * gpg2-debugsource-2.4.4-150600.3.15.1 * gpg2-tpm-debuginfo-2.4.4-150600.3.15.1 * dirmngr-debuginfo-2.4.4-150600.3.15.1 * gpg2-debuginfo-2.4.4-150600.3.15.1 * gpg2-tpm-2.4.4-150600.3.15.1 * openSUSE Leap 15.6 (noarch) * gpg2-lang-2.4.4-150600.3.15.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dirmngr-2.4.4-150600.3.15.1 * gpg2-2.4.4-150600.3.15.1 * gpg2-debugsource-2.4.4-150600.3.15.1 * dirmngr-debuginfo-2.4.4-150600.3.15.1 * gpg2-debuginfo-2.4.4-150600.3.15.1 * Basesystem Module 15-SP7 (noarch) * gpg2-lang-2.4.4-150600.3.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dirmngr-2.4.4-150600.3.15.1 * gpg2-2.4.4-150600.3.15.1 * gpg2-debugsource-2.4.4-150600.3.15.1 * dirmngr-debuginfo-2.4.4-150600.3.15.1 * gpg2-debuginfo-2.4.4-150600.3.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gpg2-lang-2.4.4-150600.3.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dirmngr-2.4.4-150600.3.15.1 * gpg2-2.4.4-150600.3.15.1 * gpg2-debugsource-2.4.4-150600.3.15.1 * dirmngr-debuginfo-2.4.4-150600.3.15.1 * gpg2-debuginfo-2.4.4-150600.3.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gpg2-lang-2.4.4-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24882.html * https://bugzilla.suse.com/show_bug.cgi?id=1256389 * https://bugzilla.suse.com/show_bug.cgi?id=1257396 . Critical security fix for gpg2 addressing buffer overflow in TPM. Update recommended for SUSE users as vulnerabilities may expose systems.. gpg2 security update,SUSE vulnerabilities,buffer overflow fix,TPM security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has three security fixes can now be installed.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:0378-1 Release Date: 2026-02-04T07:38:17Z Rating: important References: * bsc#1255715 * bsc#1256244 * bsc#1256389 * bsc#1256390 Cross-References: * CVE-2025-68973 CVSS scores: * CVE-2025-68973 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68973 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for gpg2 fixes the following issues: * CVE-2025-68973: Fixed possile memory corruption in the armor parser [T7906] (bsc#1255715) * Fixed GnuPG Accepting Path Separators and Path Traversals in Literal Data (bsc#1256389) * Fixed Cleartext Signature Forgery in the NotDashEscaped header implementation in GnuPG (bsc#1256390) * Fixed error out on unverified output for non-detached signatures [T7903] (bsc#1256244) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-378=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-378=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gpg2-debugsource-2.0.24-9.17.1 *gpg2-2.0.24-9.17.1 * gpg2-debuginfo-2.0.24-9.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gpg2-lang-2.0.24-9.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gpg2-debugsource-2.0.24-9.17.1 * gpg2-2.0.24-9.17.1 * gpg2-debuginfo-2.0.24-9.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gpg2-lang-2.0.24-9.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68973.html * https://bugzilla.suse.com/show_bug.cgi?id=1255715 * https://bugzilla.suse.com/show_bug.cgi?id=1256244 * https://bugzilla.suse.com/show_bug.cgi?id=1256389 * https://bugzilla.suse.com/show_bug.cgi?id=1256390 . An important security update for gpg2 resolves one critical issue and three fixes. Upgrade for enhanced protection.. SUSE gpg2 security patch important update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.