Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91170.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91170
Upstream
  • CVE-2026-57062
Published
2026-06-23T18:18:10Z
Modified
2026-09-02T06:51:55Z
Summary
CVE-2026-57062 affecting package gnupg2 for versions less than 2.4.9-3
Details

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

References

Affected packages

Azure Linux:3 / gnupg2

Package

Name
gnupg2
Purl
pkg:rpm/azure-linux/gnupg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.9-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91170.json"