CVE-2026-24883
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig-data[] set to a
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig-data[] set to a NULL value, leading to a denial of service (application crash).
LOW · CVSS 3.7
EPSS 0.00022
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules3
YARA rules0