Back Linuxsecurity Ubuntu 26.04 LTS GnuPG Important Message Integrity Bypass CVE-2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
GnuPG could allow encrypted messages to be forged under certain circumstances. Software Description: - gnupg2: GNU privacy guard - a free PGP replacement Details: It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity checks.
GnuPG could allow encrypted messages to be forged under certain
Software Description:
- gnupg2: GNU privacy guard - a free PGP replacement
It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gpgsm 2.4.8-4ubuntu3.1 Ubuntu 24.04 LTS gpgsm 2.4.4-2ubuntu17.6 In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8720-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
