In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
{
"license": "CC-BY-4.0",
"sources": [
{
"published": "2025-12-28T17:16:01.500Z",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68973",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-68973",
"database_specific": {
"status": "Modified"
},
"modified": "2026-01-14T19:16:46.857Z",
"id": "CVE-2025-68973",
"imported": "2026-05-27T16:52:13.925Z"
},
{
"published": "2025-12-28T18:30:26Z",
"html_url": "https://github.com/advisories/GHSA-pj23-86ww-f72p",
"url": "https://api.github.com/advisories/GHSA-pj23-86ww-f72p",
"modified": "2026-01-14T21:35:07Z",
"imported": "2026-05-27T16:52:15.936Z",
"id": "GHSA-pj23-86ww-f72p"
},
{
"published": "2025-12-28T16:19:11Z",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205519",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-205519",
"modified": "2026-04-30T03:55:53Z",
"imported": "2026-05-27T16:52:14.561Z",
"id": "EUVD-2025-205519"
}
]
}