Input validation error in GnuPG - CVE-2025-30258
Published: April 4, 2025
Vulnerability details
The vulnerability allows a remote attacker to disable signature verification.
The vulnerability exists due to an error when handling subkey data. A remote attacker can trick the victim into importing a specially crafted certificate with subkey data that lacks a valid backsig or that has incorrect usage flags and disable signature verification for other signing keys.
Affected software
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap
Ubuntu
openEuler
Anolis OS
gnupg2 (Ubuntu package)
gnupg (Ubuntu package)
gpg (Ubuntu package)
gnupg2-help
gnupg2-debugsource
gnupg2-debuginfo
gnupg2
gpg2
gpg2-debugsource
gpg2-debuginfo
gpg2-lang
dirmngr-debuginfo
dirmngr
gnupg2-smime
Cloud Pak for Data System - Cyclops
How to mitigate CVE-2025-30258
gnupg2 (Ubuntu package) - addressed in versions 2.1.11-6ubuntu2.1+esm2, 2.2.4-1ubuntu1.6+esm1, 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gnupg (Ubuntu package) - addressed in versions 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gpg (Ubuntu package) - addressed in versions 2.2.19-3ubuntu2.4, 2.2.27-3ubuntu2.3, 2.4.4-2ubuntu17.2, 2.4.4-2ubuntu18.2
gnupg2-help - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2-debugsource - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2-debuginfo - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gnupg2 - addressed in versions 2.2.21-9, 2.2.32-7, 2.4.3-6, 2.4.3-8
gpg2 - update to 2.2.27-150300.3.13.1
gpg2-debugsource - update to 2.2.27-150300.3.13.1
gpg2-debuginfo - update to 2.2.27-150300.3.13.1
gpg2-lang - update to 2.2.27-150300.3.13.1
dirmngr-debuginfo - update to 2.2.27-150300.3.13.1
dirmngr - update to 2.2.27-150300.3.13.1
gnupg2-smime - addressed in versions 2.4.3-2, 2.4.3-3
gnupg2 - addressed in versions 2.4.3-2, 2.4.3-3
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
External References
Related Security Bulletins
- Signature verification bypass in GnuPG
- Ubuntu update for gnupg2
- openEuler 24.03 LTS SP1 update for gnupg2
- openEuler 24.03 LTS update for gnupg2
- openEuler 20.03 LTS SP4 update for gnupg2
- openEuler 22.03 LTS SP4 update for gnupg2
- openEuler 22.03 LTS SP3 update for gnupg2
- Anolis OS update for gnupg2
- Anolis OS update for gnupg2
- SUSE update for gpg2
- Ubuntu update for gnupg2
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops