CVE-2026-24881

HIGH

GnuPG 2.5.13-2.5.16 and gpg4win 5.0.0-5.0.0 - Stack-based Buffer Overflow via Oversized CMS Wrapped Session Key

Title source: llm
STIX 2.1

Description

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

References (2)

Core 2
Core References
Exploit, Product
https://dev.gnupg.org/T8044

Scores

CVSS v3 8.1
EPSS 0.0147
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (2)
gnupg/gnupg 2.5.13 - 2.5.17
gpg4win/gpg4win 5.0.0 - 5.0.1
Published Jan 27, 2026
Tracked Since Feb 18, 2026