Out-of-bounds write in GnuPG - CVE-2025-68973

 

Out-of-bounds write in GnuPG - CVE-2025-68973

Published: December 29, 2025


Vulnerability identifier: #VU120611
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68973
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error within the armor_filter() function in g10/armor.c. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

GnuPG
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Financial Transaction Manager for RedHat OpenShift
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnupg (Ubuntu package)
gnupg2-smime
gnupg2
gnupg2 (Red Hat package)
gpg2-lang
gpg2-debuginfo
gpg2
gpg2-debugsource
gnupg2 (Ubuntu package)
app-crypt/gnupg
AppDynamics Java Agent
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
IBM TXSeries for Multiplatforms
Oracle Communications Cloud Native Core Console
IBM CICS TX Standard
Juniper Junos Space

How to mitigate CVE-2025-68973

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF05
AppDynamics Java Agent - update to 26.1.0
AppDynamics NodeJS Agent - update to 25.12.1
Service Interconnect - update to 1
gnupg (Ubuntu package) - addressed in versions 1.4.16-1ubuntu2.6+esm2, 1.4.20-1ubuntu3.3+esm3
gnupg2-smime - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 (Red Hat package) - addressed in versions 2.0.22-5.el7_9.1, 2.2.9-1.el8_2.1, 2.2.20-2.el8_4.1, 2.2.20-3.el8_6.1, 2.2.20-3.el8_8.1, 2.2.20-4.el8_10, 2.3.3-2.el9_0.1, 2.3.3-2.el9_2.1, 2.3.3-4.el9_4.1, 2.3.3-5.el9_7, 2.4.5-2.el10_0.1, 2.4.5-3.el10_1
gpg2-lang - update to 2.0.24-9.17.1
gpg2-debuginfo - update to 2.0.24-9.17.1
gpg2 - update to 2.0.24-9.17.1
gpg2-debugsource - update to 2.0.24-9.17.1
gnupg2 (Ubuntu package) - addressed in versions 2.1.11-6ubuntu2.1+esm3, 2.2.4-1ubuntu1.6+esm2, 2.2.19-3ubuntu2.5+esm1, 2.2.27-3ubuntu2.5, 2.4.4-2ubuntu17.4, 2.4.4-2ubuntu23.2, 2.4.8-2ubuntu2.1
app-crypt/gnupg - update to 2.5.14
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix18
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Juniper Junos Space - update to 26.1R1 Patch V1

External References

Related Security Bulletins