VDB

GCVE-110-MAGEIA-2025-133

GCVE-110-MAGEIA-2025-133
Advisory Published
Vulnetix · Advisory published April 12, 2025
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS". (CVE-2025-30258)

Affected Products

VendorProductVersionsPlatforms
Mageiagnupg20 (affected), 2.3.8-1.3.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›