CVE Vulnerabilities

CVE-2025-68973

Multiple Operations on Resource in Single-Operation Context

Published: Dec 28, 2025 | Modified: Jan 14, 2026
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Weakness

The product performs the same operation on a resource two or more times, when the operation should only be applied once.

Affected Software

NameVendorStart VersionEnd Version
GnupgGnupg*2.4.8 (including)
Red Hat Enterprise Linux 10RedHatgnupg2-0:2.4.5-3.el10_1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatgnupg2-0:2.4.5-2.el10_0.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatgnupg2-0:2.0.22-5.el7_9.1*
Red Hat Enterprise Linux 8RedHatgnupg2-0:2.2.20-4.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatgnupg2-0:2.2.9-1.el8_2.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatgnupg2-0:2.2.20-2.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatgnupg2-0:2.2.20-2.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatgnupg2-0:2.2.20-3.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatgnupg2-0:2.2.20-3.el8_8.1*
Red Hat Enterprise Linux 9RedHatgnupg2-0:2.3.3-5.el9_7*
Red Hat Enterprise Linux 9RedHatgnupg2-0:2.3.3-5.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatgnupg2-0:2.3.3-2.el9_0.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatgnupg2-0:2.3.3-2.el9_2.1*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatgnupg2-0:2.3.3-4.el9_4.1*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatgnupg2-0:2.3.3-4.el9_6.1*
Compliance Operator 1RedHatcompliance/openshift-compliance-content-rhel8:sha256:c3be1b6c7f4a941ea8ce04911a6ad4e131d68edaf740202edd3d8e81a5ada121*
Compliance Operator 1RedHatcompliance/openshift-compliance-must-gather-rhel8:sha256:c630e73e617cf3ae94ded4961051c230ac51cab6c65f2067811e193aab489e8a*
Compliance Operator 1RedHatcompliance/openshift-compliance-openscap-rhel8:sha256:05c4770c79444de006d6ee9fa05c678e2bc26bda6aa3306c5149e80e741c07b3*
Compliance Operator 1RedHatcompliance/openshift-compliance-rhel8-operator:sha256:68ba04c2a97a1dbe3780ed8c6b86af3079584211e3d466f00dcd7a509281f371*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-central-db-rhel8:sha256:452b98b484516602e84835289b97d3ce5bfea4de66996fc66381a74e5f47ab44*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-collector-rhel8:sha256:97949783533ac35c4c48c3bdfcb5306853779e82b101e52fdc2f95923d4d071f*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-main-rhel8:sha256:fe5172976364ca5ef1bd83d25b5a51497d51782ef30706ccbceae3db64d10019*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-rhel8-operator:sha256:f23f9417f4dc4631bb2ab5e51e95d3a28ea7511f96a12f5d717353db4a1b40cd*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:sha256:678b96caceeb30a64c2f43395ab291e3035fa122d46eb9d2289e77bfc6b4c3b2*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:sha256:cc3f28d099d73edfd4a234b5c6bdd52299a7b3fec9b25275aca413b64c9320e3*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-scanner-rhel8:sha256:87359ad896ce3ecce5da9763a34f18b0481cbad50b4f3b0130b948e57645f818*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:e7e8edfbe4e6a55628f4d161d42d375f41e45e9bac792e1d33aadb3dbcafe471*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:ec4c412b018affc913dd6e50fa1ecaba47993619102a235572d30eb354af3599*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-central-db-rhel8:sha256:294c8f3d3cce71c22e6bde11783c04fa5db2ae19ad2a741c418005faa41da67a*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-collector-rhel8:sha256:cfb6a722aa6ede9218d9d7a28c7aae1b1455bc0ba5a41ba488e95ee504cccd70*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-main-rhel8:sha256:e87ce042d9afb90c643de99cfaa98314230a2d9a01ad1230cd0596413991f4f5*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-rhel8-operator:sha256:1e9116742efaed46b4b93ba1ff8eb026ffa5bbe5146690d020389b95bec77051*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:sha256:0f27626c8a671458174b6a3dc08268ec13f1b1ce297ca26b085a5799971470d6*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:sha256:34d1530a0759075f9a6d7cb31d45efac05575e0db2ea43adc3379f24b1524060*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-rhel8:sha256:e5e8360e4078c425988ac07bc24860e5361b6e119f5fa54370d0775a60da0f9d*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:a75bba630478e2466c371b78ffce02ad116cc872bbe78624cd3438e45f47f93e*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:461fee74ff86feaf21bda5d170975b185758cb891307e8e5e5930985a2191307*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-central-db-rhel8:sha256:f4141ca6948e53983b0aef57965bed68be81db2ef84ca4fca597e3f5655ecd7d*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-collector-rhel8:sha256:f5bbdaab3899347f0199211c97f3643bc0aed644d7f2117b22bce1bb61ea7838*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-main-rhel8:sha256:25bb4a371c5656d01a53060df46b7fbb5a287fe843c08581be69fb42ff5ec5dd*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-rhel8-operator:sha256:2d7d654755857e5a164827f2bbc022d1c23f7229b4164faa5c61e852c1706800*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:sha256:7a49b9e8ea59229abd9c73c7c0c89ca4e6ed4b30ff8c3b5867c7aaf861658bf2*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:sha256:552b628dee91632aeae32b09add80d1293ff6210585ec1469e1181660ee626e9*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-rhel8:sha256:5f83884b0a2b48f34e14b949f43e68ad4b99cb8d228bec74b5126b89cc007808*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:ec5aa99bc9c1fdc57be287f9402cbcdd31274eeac7bc158615c0c61a9fa7f3fe*
Red Hat Advanced Cluster Security 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:b88a4d77f26b9f230d8abbc06aa0a3a1cde6df903a6ef797ee18efb81e2674ac*
Red Hat Ceph Storage 7RedHatrhceph/rhceph-7-rhel9:sha256:7593f0bc7a6b312b5b686f0077443f11e9952128801809828e8bd3a73314c116*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:sha256:c1c3e3e46bb57c2c99378b7336aa2c2015b7279dcb3df7fdccc8c3dee1522ba6*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:sha256:519d4fe184cebe5152f840e9f609fa4705590656ac9bcace2e2e17622ab7e6a8*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:4ba29e3e7565cfdfdedcc558bc8495398cee07742fda133b0bc04fd657b908cd*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:sha256:975a1e501a8520df83f3f4114e72a71384ff1866ec99c7a45fffbf8c76ef5cbc*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:sha256:83e8b356eb4697a81ff8c6764dc976862800f4c78122a606173340a6e105a4fe*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:sha256:409a64405669fd11ad8700356243762a3507430f9bba4100bb92765d4482b7e5*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:sha256:df709663b581b740006c6ea4b297978932874eade1563c3952e0594e926aa5f8*
GnupgUbuntuesm-infra-legacy/trusty*
GnupgUbuntuesm-infra/xenial*
GnupgUbuntuupstream*
Gnupg2Ubuntudevel*
Gnupg2Ubuntuesm-infra/bionic*
Gnupg2Ubuntuesm-infra/focal*
Gnupg2Ubuntuesm-infra/xenial*
Gnupg2Ubuntujammy*
Gnupg2Ubuntunoble*
Gnupg2Ubuntuplucky*
Gnupg2Ubuntuquesting*
Gnupg2Ubuntuupstream*

References