Key validity not computed when key is certified by a trusted "certify-only" key (regression due to patch for CVE-2025-30258) References: - https://bugs.mageia.org/show_bug.cgi?id=34458 . MGASA-2025-0206 - Updated gnupg2 packages fix security vulnerabilities Publication date: 11 Jul 2025 URL: https://advisories.mageia.org/MGASA-2025-0206.html Type: security Affected Mageia releases: 9 Key validity not computed when key is certified by a trusted "certify-only" key (regression due to patch for CVE-2025-30258) References: - https://bugs.mageia.org/show_bug.cgi?id=34458 - https://ubuntu.com/security/notices/USN-7412-2 SRPMS: - 9/core/gnupg2-2.3.8-1.4.mga9 . Updated gnupg2 packages resolve key validity issues due to a trusted key certification problem in Mageia 9.. gnupg2 packages, Mageia security advisory, key certification error, security update. . Severity: Important. LinuxSecurity.com Team
As part of the development of GnuPG 1.2.2, a bug was discovered in the key validation code.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-04 - - - --------------------------------------------------------------------- PACKAGE : gnupg SUMMARY : key validity bug DATE : 2003-05-16 11:55 UTC VERSIONS AFFECTED : =gnupg-1.2.2 CVE : CAN-2003-0255 - - - --------------------------------------------------------------------- - From advisory: "As part of the development of GnuPG 1.2.2, a bug was discovered in the key validation code. This bug causes keys with more than one user ID to give all user IDs on the key the amount of validity given to the most-valid key." Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105215110111174&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-crypt/gnupg upgrade to gnupg-1.2.2 as follows: emerge sync emerge gnupg emerge clean - - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.