DEBIAN-CVE-2026-57062

Source
https://security-tracker.debian.org/tracker/CVE-2026-57062
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-57062.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-57062
Upstream
  • CVE-2026-57062
Published
2026-06-23T18:18:10Z
Modified
2026-09-14T17:03:20Z
Severity
  • 2.9 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

References

Affected packages

Debian:12 / gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.40-1.1
2.2.40-1.1+deb12u1
2.2.40-1.1+deb12u2
2.2.40-1.1+hurd.1
2.2.40-1.1+loong64
2.2.40-2
2.2.40-3
2.2.43-1
2.2.43-2
2.2.43-3
2.2.43-4
2.2.43-5
2.2.43-6
2.2.43-7
2.2.43-8
2.2.44-1
2.2.45-1
2.2.45-2
2.2.45-3
2.2.46~pre1-1
2.2.46-1
2.2.46-2
2.2.46-3
2.2.46-4
2.2.46-5
2.2.46-6
2.3.1-1
2.4.3-2
2.4.4-1
2.4.4-2
2.4.4-3
2.4.4-4
2.4.5-1
2.4.5-2
2.4.5-3
2.4.6-1
2.4.7-1
2.4.7-2
2.4.7-3
2.4.7-4
2.4.7-5
2.4.7-6
2.4.7-7
2.4.7-8
2.4.7-9
2.4.7-10
2.4.7-11
2.4.7-12
2.4.7-13
2.4.7-14
2.4.7-15
2.4.7-16
2.4.7-17
2.4.7-18
2.4.7-19
2.4.7-20
2.4.7-21
2.4.8-1
2.4.8-2
2.4.8-3
2.4.8-4
2.4.8-5
2.4.8-6
2.4.9-1
2.4.9-2
2.4.9-3
2.4.9-4
2.4.9-5
2.4.9-6
2.4.9-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-57062.json"

Debian:13 / gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.7-21
2.4.7-21+deb13u1
2.4.8-1
2.4.8-2
2.4.8-3
2.4.8-4
2.4.8-5
2.4.8-6
2.4.9-1
2.4.9-2
2.4.9-3
2.4.9-4
2.4.9-5
2.4.9-6
2.4.9-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-57062.json"

Debian:14 / gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.9-5

Affected versions

2.*
2.4.7-21
2.4.8-1
2.4.8-2
2.4.8-3
2.4.8-4
2.4.8-5
2.4.8-6
2.4.9-1
2.4.9-2
2.4.9-3
2.4.9-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-57062.json"