CVE-2026-24882

Source
https://cve.org/CVERecord?id=CVE-2026-24882
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24882.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24882
Downstream
AZL (2)
BELL (1)
CGA (2)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
OESA (4)
openSUSE (2)
RHSA (2)
RLSA (1)
ROOT (3)
SUSE (5)
UBUNTU (1)
Related
Published
2026-01-27T18:40:18Z
Modified
2026-08-14T21:42:01Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

Database specific
{
    "cna_assigner":  "mitre",
    "cwe_ids":  [
        "CWE-121"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24882.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "2.5.17"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "fixed":  "2.5.17"
                }
            ],
            "source":  "CPE_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "fixed":  "2.5.17"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / git.gnupg.org/gpg4win.git

Affected ranges

Type
GIT
Repo
git://git.gnupg.org/gpg4win.git
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gpg4win:gpg4win:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "5.0.0"
        },
        {
            "fixed":  "5.0.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

gpg4win-5.*
gpg4win-5.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24882.json"