Out-of-bounds write in GnuPG - CVE-2025-68973
Published: December 29, 2025
Vulnerability identifier: #VU120611
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68973
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within the armor_filter() function in g10/armor.c. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
GnuPG
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Financial Transaction Manager for RedHat OpenShift
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnupg (Ubuntu package)
gnupg2-smime
gnupg2
gnupg2 (Red Hat package)
gpg2-lang
gpg2-debuginfo
gpg2
gpg2-debugsource
gnupg2 (Ubuntu package)
app-crypt/gnupg
AppDynamics Java Agent
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
IBM TXSeries for Multiplatforms
Oracle Communications Cloud Native Core Console
IBM CICS TX Standard
Juniper Junos Space
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Financial Transaction Manager for RedHat OpenShift
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
gnupg (Ubuntu package)
gnupg2-smime
gnupg2
gnupg2 (Red Hat package)
gpg2-lang
gpg2-debuginfo
gpg2
gpg2-debugsource
gnupg2 (Ubuntu package)
app-crypt/gnupg
AppDynamics Java Agent
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
IBM TXSeries for Multiplatforms
Oracle Communications Cloud Native Core Console
IBM CICS TX Standard
Juniper Junos Space
How to mitigate CVE-2025-68973
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF05
AppDynamics Java Agent - update to 26.1.0
AppDynamics NodeJS Agent - update to 25.12.1
Service Interconnect - update to 1
gnupg (Ubuntu package) - addressed in versions 1.4.16-1ubuntu2.6+esm2, 1.4.20-1ubuntu3.3+esm3
gnupg2-smime - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 (Red Hat package) - addressed in versions 2.0.22-5.el7_9.1, 2.2.9-1.el8_2.1, 2.2.20-2.el8_4.1, 2.2.20-3.el8_6.1, 2.2.20-3.el8_8.1, 2.2.20-4.el8_10, 2.3.3-2.el9_0.1, 2.3.3-2.el9_2.1, 2.3.3-4.el9_4.1, 2.3.3-5.el9_7, 2.4.5-2.el10_0.1, 2.4.5-3.el10_1
gpg2-lang - update to 2.0.24-9.17.1
gpg2-debuginfo - update to 2.0.24-9.17.1
gpg2 - update to 2.0.24-9.17.1
gpg2-debugsource - update to 2.0.24-9.17.1
gnupg2 (Ubuntu package) - addressed in versions 2.1.11-6ubuntu2.1+esm3, 2.2.4-1ubuntu1.6+esm2, 2.2.19-3ubuntu2.5+esm1, 2.2.27-3ubuntu2.5, 2.4.4-2ubuntu17.4, 2.4.4-2ubuntu23.2, 2.4.8-2ubuntu2.1
app-crypt/gnupg - update to 2.5.14
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix18
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Juniper Junos Space - update to 26.1R1 Patch V1
AppDynamics Java Agent - update to 26.1.0
AppDynamics NodeJS Agent - update to 25.12.1
Service Interconnect - update to 1
gnupg (Ubuntu package) - addressed in versions 1.4.16-1ubuntu2.6+esm2, 1.4.20-1ubuntu3.3+esm3
gnupg2-smime - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 - addressed in versions 2.0.22-5, 2.2.20-4, 2.4.3-4
gnupg2 (Red Hat package) - addressed in versions 2.0.22-5.el7_9.1, 2.2.9-1.el8_2.1, 2.2.20-2.el8_4.1, 2.2.20-3.el8_6.1, 2.2.20-3.el8_8.1, 2.2.20-4.el8_10, 2.3.3-2.el9_0.1, 2.3.3-2.el9_2.1, 2.3.3-4.el9_4.1, 2.3.3-5.el9_7, 2.4.5-2.el10_0.1, 2.4.5-3.el10_1
gpg2-lang - update to 2.0.24-9.17.1
gpg2-debuginfo - update to 2.0.24-9.17.1
gpg2 - update to 2.0.24-9.17.1
gpg2-debugsource - update to 2.0.24-9.17.1
gnupg2 (Ubuntu package) - addressed in versions 2.1.11-6ubuntu2.1+esm3, 2.2.4-1ubuntu1.6+esm2, 2.2.19-3ubuntu2.5+esm1, 2.2.27-3ubuntu2.5, 2.4.4-2ubuntu17.4, 2.4.4-2ubuntu23.2, 2.4.8-2ubuntu2.1
app-crypt/gnupg - update to 2.5.14
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix18
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Juniper Junos Space - update to 26.1R1 Patch V1
External References
Related Security Bulletins
- Multiple vulnerabilities in GnuPG
- Gentoo update for GnuPG
- Ubuntu update for gnupg2
- Ubuntu update for gnupg
- Red Hat Enterprise Linux 10 update for gnupg2
- Red Hat Enterprise Linux 9 update for gnupg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Anolis OS update for gnupg2
- Red Hat Enterprise Linux 9 update for gnupg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Red Hat Enterprise Linux 10 update for gnupg2
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for gnupg2
- Red Hat Enterprise Linux 9 update for gnupg2
- Red Hat Enterprise Linux 9 update for gnupg2
- SUSE update for gpg2
- Anolis OS update for gnupg2
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- Anolis OS update for gnupg2
- Multiple vulnerabilities in IBM QRadar SIEM
- Splunk AppDynamics Java Agent update for third-party components
- Splunk AppDynamics NodeJS Agent update for third-party components
- Multiple vulnerabilities in Service Interconnect
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Certificate Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Junos Space