Disputed by GnuPG maintainer Werner Koch. The vulnerability involves form feed
character handling in cleartext signatures. The maintainer states this is "wrong
usage of a tool or social engineering" and not a real vulnerability.
See: https://gnupg.org/blog/20251226-cleartext-signatures.html
Debian classifies this as "Minor issue" with no fix planned.
No fix exists in any Debian version (including sid).