Skip to content
Ubuntu 26.04 LTS GnuPG Important Message Integrity Bypass CVE-2026

Ubuntu 26.04 LTS GnuPG Important Message Integrity Bypass CVE-2026

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

GnuPG could allow encrypted messages to be forged under certain circumstances. Software Description: - gnupg2: GNU privacy guard - a free PGP replacement Details: It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity checks.

GnuPG could allow encrypted messages to be forged under certain

Software Description:

- gnupg2: GNU privacy guard - a free PGP replacement

It was discovered that GnuPG incorrectly validated authentication tag

lengths when parsing CMS messages encrypted with AES-GCM. An attacker could

possibly use this issue to bypass message integrity checks.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gpgsm 2.4.8-4ubuntu3.1 Ubuntu 24.04 LTS gpgsm 2.4.4-2ubuntu17.6 In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8720-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)