CVE Vulnerabilities

CVE-2025-68973

Multiple Operations on Resource in Single-Operation Context

Published: Dec 28, 2025 | Modified: Jan 14, 2026
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Weakness

The product performs the same operation on a resource two or more times, when the operation should only be applied once.

Affected Software

NameVendorStart VersionEnd Version
GnupgGnupg*2.4.8 (including)
Red Hat Enterprise Linux 10RedHatgnupg2-0:2.4.5-3.el10_1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatgnupg2-0:2.4.5-2.el10_0.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatgnupg2-0:2.0.22-5.el7_9.1*
Red Hat Enterprise Linux 8RedHatgnupg2-0:2.2.20-4.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatgnupg2-0:2.2.9-1.el8_2.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatgnupg2-0:2.2.20-2.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatgnupg2-0:2.2.20-2.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatgnupg2-0:2.2.20-3.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatgnupg2-0:2.2.20-3.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatgnupg2-0:2.2.20-3.el8_8.1*
Red Hat Enterprise Linux 9RedHatgnupg2-0:2.3.3-5.el9_7*
Red Hat Enterprise Linux 9RedHatgnupg2-0:2.3.3-5.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatgnupg2-0:2.3.3-2.el9_0.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatgnupg2-0:2.3.3-2.el9_2.1*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatgnupg2-0:2.3.3-4.el9_4.1*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatgnupg2-0:2.3.3-4.el9_6.1*
OpenShift Compliance Operator 1RedHatcompliance/openshift-compliance-content-rhel8:1769190317*
OpenShift Compliance Operator 1RedHatcompliance/openshift-compliance-must-gather-rhel8:1769458927*
OpenShift Compliance Operator 1RedHatcompliance/openshift-compliance-openscap-rhel8:1769483309*
OpenShift Compliance Operator 1RedHatcompliance/openshift-compliance-rhel8-operator:1769458916*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-central-db-rhel8:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-collector-rhel8:1769010086*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-main-rhel8:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-rhel8-operator:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:1769125501*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-scanner-rhel8:1769125501*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:1769615659*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-central-db-rhel8:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-collector-rhel8:1769065259*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-main-rhel8:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-rhel8-operator:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:1769492398*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-rhel8:1769492398*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:1770250889*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-central-db-rhel8:1770074713*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-collector-rhel8:1769100379*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-main-rhel8:1770074713*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-rhel8-operator:1770074713*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-roxctl-rhel8:1770074713*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-db-rhel8:1769577723*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-rhel8:1769577723*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-db-rhel8:1770074713*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-scanner-v4-rhel8:1770074713*
Red Hat Ceph Storage 7RedHatrhceph/rhceph-7-rhel9:1769508455*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:1769512383*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1769104765*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1769111774*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1770740405*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1770808689*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1770807477*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1770646925*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1770808765*
GnupgUbuntuesm-infra-legacy/trusty*
GnupgUbuntuesm-infra-legacy/xenial*
GnupgUbuntuesm-infra/xenial*
GnupgUbuntuupstream*
Gnupg2Ubuntudevel*
Gnupg2Ubuntuesm-infra-legacy/xenial*
Gnupg2Ubuntuesm-infra/bionic*
Gnupg2Ubuntuesm-infra/focal*
Gnupg2Ubuntuesm-infra/xenial*
Gnupg2Ubuntujammy*
Gnupg2Ubuntunoble*
Gnupg2Ubuntuplucky*
Gnupg2Ubuntuquesting*
Gnupg2Ubuntuupstream*

References