CVE-2024-53856

HIGH

rPGP <0.14.1 - Use After Free

Title source: llm
STIX 2.1

Description

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-130 CWE-148 CWE-617
Status published
Products (2)
crates.io/pgp 0 - 0.14.1crates.io
rpgp/rpgp < 0.14.1
Published Dec 05, 2024
Tracked Since Feb 18, 2026