CVE-2026-41989
MEDIUMLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Published: 4/23/2026Modified: 7/14/2026
References (5)
https://dev.gnupg.org/T8211Broken Linkhttps://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.htmlThird Party Advisoryhttps://www.openwall.com/lists/oss-security/2026/04/21/1Third Party Advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-019113.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html