GnuPG Vulnerability in Ubuntu 26.04 LTS Allows Message Forgery

GnuPG Vulnerability in Ubuntu 26.04 LTS Allows Message Forgery

First seen 3 Sep 2026, 17:39 UTC UbuntuLinuxsecuritylaunchpad.net 45.0

Article Content

Browse articles
ThreatCluster

A vulnerability in GnuPG was discovered that incorrectly validates authentication tag lengths when parsing CMS messages encrypted with AES-GCM. This flaw could allow attackers to bypass message integrity checks, potentially leading to forged encrypted messages. The affected software is GnuPG version 2.4.8-4ubuntu3.1 on Ubuntu 26.04 LTS and version 2.4.4-2ubuntu17.6 on Ubuntu 24.04 LTS. Users are advised to update their systems to mitigate this risk. A standard system update will apply the necessary changes to secure the systems. The vulnerability is identified as CVE-2026-XXXX, and the issue has been acknowledged in both Linuxsecurity and Ubuntu advisories. Immediate action is recommended to prevent potential exploitation.

Key Points: • GnuPG vulnerability allows message forgery via improper authentication tag validation. • Affected systems include Ubuntu 26.04 LTS and 24.04 LTS with specific GnuPG versions. • Users should perform a standard system update to patch the vulnerability.

Timeline

2026-09-03
GnuPG vulnerability disclosed
A flaw in GnuPG was identified that allows message integrity checks to be bypassed, affecting Ubuntu systems.
Linuxsecurity
2026-09-03
Ubuntu Security Notice USN-8720-1 issued
Ubuntu released an advisory detailing the GnuPG vulnerability and recommended updates for affected systems.
Ubuntu