Skip to content
Ubuntu 16.04 LTS: GnuPG Critical Remote Code Exec Vulnerability USN-7946

Ubuntu 16.04 LTS: GnuPG Critical Remote Code Exec Vulnerability USN-7946

Linuxsecurity •LinuxSecurity Advisories • January 8, 2026

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: GnuPG could be made to crash or run programs if it received specially crafted network traffic. Software Description: - gnupg: GNU privacy guard - a free PGP replacement Details: USN-7946-1 fixed vulnerabilities in GnuPG 2.x. This update provides the corresponding updates for GnuPG 1.x. Original advisory details: It was discovered that GnuPG incorrectly handled crafted input. A remote attacker could possibly use this issue to crash the program, or execute arbitrary code.

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: GnuPG could be made to crash or run programs if it received specially crafted network traffic. Software Description: - gnupg: GNU privacy guard - a free PGP replacement Details: USN-7946-1 fixed vulnerabilities in GnuPG 2.x. This update provides the corresponding updates for GnuPG 1.x. Original advisory details: It was discovered that GnuPG incorrectly handled crafted input. A remote attacker could possibly use this issue to crash the program, or execute arbitrary code.

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS gnupg 1.4.20-1ubuntu3.3+esm3 Available with Ubuntu Pro gpgv 1.4.20-1ubuntu3.3+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS gnupg 1.4.16-1ubuntu2.6+esm2 Available with Ubuntu Pro gpgv 1.4.16-1ubuntu2.6+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS gnupg 1.4.20-1ubuntu3.3+esm3 Available with Ubuntu Pro gpgv 1.4.20-1ubuntu3.3+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS gnupg 1.4.16-1ubuntu2.6+esm2 Available with Ubuntu Pro gpgv 1.4.16-1ubuntu2.6+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2025-68973

Extracted Entities

Attack Types (1)

Companies (1)