GnuPG is a complete and free implementation of the OpenPGP standard as defined by RFC4880 (also known as PGP). GnuPG enables encryption and signing of data and communication, and features a versatile key management system as well as access modules for public key directories.
Security Fix(es):
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."(CVE-2025-30258)
{
"severity": "Low"
}{
"x86_64": [
"gnupg2-2.4.3-8.oe2403sp1.x86_64.rpm",
"gnupg2-debuginfo-2.4.3-8.oe2403sp1.x86_64.rpm",
"gnupg2-debugsource-2.4.3-8.oe2403sp1.x86_64.rpm"
],
"src": [
"gnupg2-2.4.3-8.oe2403sp1.src.rpm"
],
"aarch64": [
"gnupg2-2.4.3-8.oe2403sp1.aarch64.rpm",
"gnupg2-debuginfo-2.4.3-8.oe2403sp1.aarch64.rpm",
"gnupg2-debugsource-2.4.3-8.oe2403sp1.aarch64.rpm"
],
"noarch": [
"gnupg2-help-2.4.3-8.oe2403sp1.noarch.rpm"
]
}