VDB
ALSA-2022%3A6602
ALSA-2022%3A6602
PUBLISHED
The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards. Security Fix(es): * gpg: Signature spoofing via status line injection (CVE-2022-34903) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | gnupg2-smime | 0, 0 |
| AlmaLinux:9 | gnupg2 | 0, 0 |
Timeline
- Sep 20, 2022 CVE Published
- Oct 14, 2022 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:6602 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-34903 third-party-advisory
- https://bugzilla.redhat.com/2102868 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2022-6602.html vendor-advisory