CVE-2025-30258

ADVISORY - ubuntu

Summary

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

EPSS Score: 0.0001 (0.008)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Check for Unusual or Exceptional Conditions

ADVISORY - redhat

Improper Check for Unusual or Exceptional Conditions


Ubuntu

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium
PackageTypeOS NameOS VersionAffected RangesFix Versions
ubuntu/gnupg2debubuntu22.04<2.2.27-3ubuntu2.32.2.27-3ubuntu2.3
ubuntu/gnupg2debubuntu24.04<2.4.4-2ubuntu17.22.4.4-2ubuntu17.2
ubuntu/gnupg2debubuntu20.04<2.2.19-3ubuntu2.42.2.19-3ubuntu2.4
ubuntu/gnupg2debubuntu25.04<2.4.4-2ubuntu232.4.4-2ubuntu23
ubuntu/gnupg2debubuntu24.10<2.4.4-2ubuntu18.22.4.4-2ubuntu18.2

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

EXPLOITABILITY SCORE

1

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

2.7low

Debian

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Red Hat

CREATED

UPDATED

EXPLOITABILITY SCORE

1.0

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

2.7low