Input validation error in GnuPG - CVE-2025-30258

 

Input validation error in GnuPG - CVE-2025-30258

Published: April 4, 2025


Vulnerability identifier: #VU106992
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30258
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disable signature verification.

The vulnerability exists due to an error when handling subkey data. A remote attacker can trick the victim into importing a specially crafted certificate with subkey data that lacks a valid backsig or that has incorrect usage flags and disable signature verification for other signing keys.


Affected software

GnuPG
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap
Ubuntu
openEuler
Anolis OS
gnupg2 (Ubuntu package)
gnupg (Ubuntu package)
gpg (Ubuntu package)
gnupg2-help
gnupg2-debugsource
gnupg2-debuginfo
gnupg2
gpg2
gpg2-debugsource
gpg2-debuginfo
gpg2-lang
dirmngr-debuginfo
dirmngr
gnupg2-smime
Cloud Pak for Data System - Cyclops

How to mitigate CVE-2025-30258

Install updates from vendor's website.

GnuPG - update to 2.5.5
gnupg2 (Ubuntu package) - addressed in versions 2.1.11-6ubuntu2.1+esm2, 2.2.4-1ubuntu1.6+esm1, 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gnupg (Ubuntu package) - addressed in versions 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gpg (Ubuntu package) - addressed in versions 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gnupg2-help - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2-debugsource - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2-debuginfo - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2 - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gpg2 - update to 2.2.27-150300.3.13.1
gpg2-debugsource - update to 2.2.27-150300.3.13.1
gpg2-debuginfo - update to 2.2.27-150300.3.13.1
gpg2-lang - update to 2.2.27-150300.3.13.1
dirmngr-debuginfo - update to 2.2.27-150300.3.13.1
dirmngr - update to 2.2.27-150300.3.13.1
gnupg2-smime - addressed in versions 2.4.3-2, 2.4.3-3
gnupg2 - addressed in versions 2.4.3-2, 2.4.3-3
Cloud Pak for Data System - Cyclops - update to 11.3.1.1

External References

Related Security Bulletins