CVE-2026-57062

Publication date 23 June 2026

Last updated 29 June 2026


Ubuntu priority

Cvss 3 Severity Score

2.9 · Low

Score breakdown

Description

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Read the notes from the security team

Why is this CVE low priority?

This is a low severity issue

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
gnupg2 26.04 LTS resolute
Vulnerable
25.10 questing Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected

Notes


mdeslaur

this is a low severity issue

Severity score breakdown

CVSS version: CVSS v3.0

Base score 2.9 · Low

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N


Access our resources on patching vulnerabilities