CVE-2026-24882

HIGH

GnuPG 2.5.13-2.5.16 - Stack-based Buffer Overflow in TPM2 Daemon PKDECRYPT Command

Title source: llm
STIX 2.1

Description

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

References (2)

Core 2
Core References
Exploit, Product
https://dev.gnupg.org/T8045

Scores

CVSS v3 8.4
EPSS 0.0039
EPSS Percentile 30.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (2)
gnupg/gnupg 2.5.13 - 2.5.17
gpg4win/gpg4win 5.0.0 - 5.0.1
Published Jan 27, 2026
Tracked Since Feb 18, 2026