CVE Vulnerabilities

CVE-2025-68973

Multiple Operations on Resource in Single-Operation Context

Published: Dec 28, 2025 | Modified: Jan 14, 2026
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
HIGH

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Weakness

The product performs the same operation on a resource two or more times, when the operation should only be applied once.

Affected Software

Name Vendor Start Version End Version
Gnupg Gnupg * 2.4.8 (including)
Red Hat Enterprise Linux 10 RedHat gnupg2-0:2.4.5-3.el10_1 *
Red Hat Enterprise Linux 8 RedHat gnupg2-0:2.2.20-4.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat gnupg2-0:2.2.9-1.el8_2.1 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat gnupg2-0:2.2.20-2.el8_4.1 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat gnupg2-0:2.2.20-2.el8_4.1 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat gnupg2-0:2.2.20-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat gnupg2-0:2.2.20-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat gnupg2-0:2.2.20-3.el8_6.1 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat gnupg2-0:2.2.20-3.el8_8.1 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat gnupg2-0:2.2.20-3.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat gnupg2-0:2.3.3-5.el9_7 *
Red Hat Enterprise Linux 9 RedHat gnupg2-0:2.3.3-5.el9_7 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat gnupg2-0:2.3.3-4.el9_4.1 *
Red Hat Enterprise Linux 9.6 Extended Update Support RedHat gnupg2-0:2.3.3-4.el9_6.1 *
Gnupg Ubuntu esm-infra-legacy/trusty *
Gnupg Ubuntu esm-infra/xenial *
Gnupg Ubuntu upstream *
Gnupg2 Ubuntu devel *
Gnupg2 Ubuntu esm-infra/bionic *
Gnupg2 Ubuntu esm-infra/focal *
Gnupg2 Ubuntu esm-infra/xenial *
Gnupg2 Ubuntu jammy *
Gnupg2 Ubuntu noble *
Gnupg2 Ubuntu plucky *
Gnupg2 Ubuntu questing *
Gnupg2 Ubuntu upstream *

References