#VU106992 Input validation error in GnuPG - CVE-2025-30258
Published: April 4, 2025
GnuPG
GNU
Description
The vulnerability allows a remote attacker to disable signature verification.
The vulnerability exists due to an error when handling subkey data. A remote attacker can trick the victim into importing a specially crafted certificate with subkey data that lacks a valid backsig or that has incorrect usage flags and disable signature verification for other signing keys.