Post #453861
2026-01-05 11:39 UTC
Details about the (ongoing) response to https://gpg.fail/ from GnuPG's side:
* https://www.gnupg.org/blog/20251226-cleartext-signatures.html
* https://dev.gnupg.org/T7906 Memory Corruption in ASCII-Armor Parsing
* https://dev.gnupg.org/T7900 (overview)
Please upgrade to GnuPG 2.5.16, 2.4.9 or #Gpg4win 5.0.0-beta479 which already have the fix for what (currently) is seen to be the only major defect: T7906.
(Researchers - Thanks! - found defects in GnuPG, Sequoia-PG, Minisign and age.)
#EndtoEndCrypto #LibrePGP #GnuPG #Security
Replies (2)
-
@DD9JN@social.darc.de 2026-01-05 13:12
@GnuPG Actually the bug was already fixed with #gnupg 2.5.14 on November 19. (For GnuPG VS-Desktop with version 3.3.3 on November 6.)
-
@kdedude@kde.social 2026-01-05 15:14
@GnuPG I'll pick up the #FreeBSD ports update this evening.