CVE-2025-68973CWE-675

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted…

High · published December 28, 2025

CVSS v3.1
7.8
EPSS
0%
Percentile
4.4
In the wild
Unconfirmed
What it is

⚡ A quirky index mishap in GnuPG could lead to an out-of-bounds write, which is like a baker accidentally adding too much yeast and having the dough overflow! Think of it as a recipe gone wrong where the chef mistakenly counts the number of eggs twice, resulting in a chaotic baking disaster. It might seem minor, but the consequences can lead to a lot of wasted ingredients—or in this case, data! An attacker could exploit this vulnerability to write data outside the intended bounds, potentially causing the program to misbehave or even crash. This could compromise the integrity of the system and lead to unpredictable behavior, leaving your sensitive data dangerously exposed.

Put simply

Think of it as a recipe gone wrong where the chef mistakenly counts the number of eggs twice, resulting in a chaotic baking disaster. It might seem minor, but the consequences can lead to a lot of wasted ingredients—or in this case, data! In GnuPG versions prior to 2.4.9, the armor_filter function in g10/armor.c improperly increments an index variable, allowing for out-of-bounds writes when processing crafted input. This flaw can potentially be exploited to manipulate memory allocation.

What to do

An attacker could exploit this vulnerability to write data outside the intended bounds, potentially causing the program to misbehave or even crash. This could compromise the integrity of the system and lead to unpredictable behavior, leaving your sensitive data dangerously exposed. To safeguard your systems, upgrade GnuPG to version 2.4.9 or later immediately. For ExtendedLTS users, ensure you are on version 2.2.51 or later. It's crucial to regularly check and apply updates to keep your software secure! You've got this! By taking these steps, you’re not just fixing a bug; you're reinforcing the security of your system! 🛡️

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00148 · 4.4th percentile
Weakness
CWE-675 · Multiple Operations on Resource in Single-Operation Context
Published
2025-12-28T16:19Z
EPSS history
Timeline
  • 28 DEC 16:19Z
    In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted…
    cvelistv5