CVE-2025-30258

Source
https://cve.org/CVERecord?id=CVE-2025-30258
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30258.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30258
Downstream
AZL (2)
CGA (26)
CLSA (3)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (1)
OESA (5)
openSUSE (1)
ROOT (2)
SUSE (9)
UBUNTU (1)
Related
Published
2025-03-19T20:15:20Z
Modified
2026-04-16T04:40:32Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30258.json"
unresolved_ranges
[
    {
        "events":  [
            {
                "introduced":  "0"
            },
            {
                "fixed":  "2.4.8"
            }
        ]
    },
    {
        "events":  [
            {
                "introduced":  "2.5.0"
            },
            {
                "fixed":  "2.5.5"
            }
        ]
    }
]