CVE-2026-57062
ADVISORY - debianSummary
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
- gnupg2 2.4.9-5 [trixie] - gnupg2 (Minor issue) [bookworm] - gnupg2 (Minor issue) [bullseye] - gnupg2 (gpgsm GCM CMS-decrypt path not present; introduced after 2.2.27) https://blog.calif.io/p/how-to-format-a-ciphertext Fixed by: https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4
EPSS Score: 0.0011 (0.015)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in