Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

FreePG Project

@freepg@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

FreePG maintains a shared patchset for #GnuPG downstream packagers to track, maintain, and apply commonly-used patches. The project goals are:

* Minimise divergence from the IETF #OpenPGP specification
* Support reading of LibrePGP artifacts for compatibility
* Fix security issues that remain unresolved upstream
* Support the maintenance needs of downstream distributions

63 Followers
39 Following
12 Posts
Joined August 27, 2025
Homepage:
https://freepg.org
Mailing List:
https://openpgp.simplelists.com/freepg
Open post
FreePG Project @freepg@infosec.exchange
· 1w ago

RE: @GnuPG@mstdn.social

Great to see RFC9980 support (which also implies RFC9580 support) landing in #GnuPG. Congratulations to the team on their hard work! 🚀

Unlike upstream GnuPG, the FreePG project does not encourage use of "LibrePGP Kyber", especially now that RFC9980 has been implemented. It is important to remember that there are no differences in the security properties between "LibrePGP Kyber" and RFC9980, but RFC9980 is interoperable with other OpenPGP software while "LibrePGP Kyber" is not.

There are several related changes to the compliance modes in this release which will have implications for FreePG, so there may be a longer delay than usual before we can release 2.5.24-freepg, but watch this space...

mstdn.social
5
0
5
0
Open post
FreePG Project @freepg@infosec.exchange
· 3mo ago

#GnuPG 2.4.9-freepg-1 has been released.

It contains backported bugfixes from upstream GnuPG 2.5.x, plus all the previous FreePG patches.

Since 31st of December last year, upstream GnuPG is no longer providing bugfix releases for the 2.4.x branch, in an attempt to encourage people to upgrade to 2.5.x. The FreePG project considers the 2.5.x branch to be experimental, primarily due to its use of non-OpenPGP algorithms by default, and is continuing to support 2.4.x by porting bugfixes from the 2.5.x and 2.2.x branches, which are both still maintained upstream.

Release Notes Noteworthy changes in version 2.4.9-freepg-1 (2026-07-02)
  • Backported several bugfixes from 2.5:

    • dirmngr: Fix a call of calloc.
    • agent: Fix the regression in pkdecrypt with TPM RSA.
    • tpm: Fix possible buffer overflow in PKDECRYPT
    • gpg: Fix armor parsing when no CRC is found.
    • gpg: Fix armored input parsing.
    • gpg: Fix handling with no CRC armor.
    • gpgsm: Require a minimum tag length for GCM decryption.
    • gpg: Fix edge case in --refresh-keys
  • Fixed several tests introduced by the "tests: add test cases for import without uid" patch.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.4.9-freepg-1

gitlab.com

gnupg-2.4.9-freepg-1 · freepg / gnupg · GitLab

3
0
3
0
Open post
FreePG Project @freepg@infosec.exchange
· 5mo ago

#GnuPG 2.5.19-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

Release Notes
=============

Noteworthy changes in version 2.5.19-freepg (2026-04-30)
-------------------------------------------------

* No FreePG-specific changes.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.19-freepg

Upstream's release notes follow.

-----

Noteworthy changes in version 2.5.19 (2026-04-24)
-------------------------------------------------

* New and extended features:

- gpg: New option --use-ocb-sym. [rGccdcdfbb37]

- gpg: New options --show-[only-]session-hash. [rGecd0f7afa1]

- gpgsm: Allow cipher mode to be part of the algo given to the
--cipher-algo option. [T3979]

- gpgsm: Emit more details when failing to check a crlDP. [T8221]

- agent: Improve pinentry behavior and texts in smartcard context.
[T6425]

- dirmngr: New keyword "clear" for --keyserver. [rG2ab4cba36c]

* Bug fixes:

- gpg: Fix edge case in --refresh-keys. [T8197]

- gpg: Don't call gcry_kdf_derive with empty passphrase. [T7739]

- gpgsm: Skip the optional PKCS#12 PBES2 keyLength parameter to
allow import of recently issued certificates by the German
Telekom. [rGc8c9604bba]

- gpgsm: Fix a bug so that a certificate can be signed using a
different algo. [rG66fdafab3c]

- gpgsm: Make GCM fully compliant in de-vs mode. [rG04fd775fce]

- gpgsm: Add a certificate chain check for de-vs compliance.
[T8188]

- gpgsm: Show rsaPSS certificates as de-vs compliant in listings.
[T8222]

- agent: Rework the trustlist reading code to finally allow a
trustlist.txt with a missing trailing LF. [T8078]

- ssh: Fix RSA padding in signature handling. [T7882,T8202]

- gpgtar: Fix -C (--directory) to check the output directory.
[T8159]

* Other changes:

- agent: Raise an error when p >= q for RSA keys to detect
incorrect generated *PGP keys. [T8171]

Release-info: https://dev.gnupg.org/T7998

infosec.exchange
4
0
5
0
Open post
FreePG Project @freepg@infosec.exchange
· 3mo ago

#GnuPG 2.5.21-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

Release notes
=============

Noteworthy changes in version 2.5.21-freepg (2026-07-03)
--------------------------------------------------------

* No FreePG-specific changes.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.21-freepg

Upstream's release notes follow.

----

Noteworthy changes in version 2.5.21 (2026-07-02)
-------------------------------------------------

* New and extended features:

- gpg, gpgsm: Use partial file on decryption, remove on failure.
Disable with "--compatibility-flags=no-partial-file-guard".
[T7873]

- gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
[T8252]

- Create a pkgversioninfo.txt file when building using the speedo
build system.

* Bug fixes:

- gpg: Fix potential use-after-free in batch key generation when
handling the keyserver URL option. [T8277]

- gpgsm: Fix regression in gpgsm_verify with expired certificates.
[T8188]

- gpgsm: Require a minimum tag length for GCM decryption.
[rG4c7e68cf3d, CVE-2026-34182]

- scd: Limit the size of returned APDU objects from faulty cards.
[T8281]

- scd: Fix condition to retrieve ATR. [rGca25a7a61b]

- scd:openpgp: Fix regression in CHV1 retry counter byte index.
[rG245330ebea]

- agent: Make batch import of Kyber keys work. [T8029]

- dirmngr: Add a validation check in get_dns_cert_standard.
[T8303]

- gpgconf: Raise an error on certain parse errors. [T8261]

- Fix use of usleep in file remove function on Windows. Regression
since 2.5.13. [rGab9ce5f5e7]

Release-info: https://dev.gnupg.org/T8262

infosec.exchange
1
0
2
0
Open post
FreePG Project @freepg@infosec.exchange
· 4mo ago

#GnuPG 2.5.20-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

Release notes
=============

Noteworthy changes in version 2.5.20-freepg (2026-05-15)
--------------------------------------------------------

* No FreePG-specific changes.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.20-freepg

Upstream's release notes follow.

------

Noteworthy changes in version 2.5.20 (2026-05-13)
-------------------------------------------------

* New and extended features:

- gpgsm: Implement GCM encryption. Note that decryption works
since version 2.3.2. [T3979]

- gpgsm: New option --attribute and server command SETATTR to
include arbitrary signed or unsigned attributes into a signature.
Enable only with libksba 1.7.0 or later. [T4537]

- gpgsm: Introduce system attribute _signingCertificateV2.
[rG0335a9cb04]

* Bug fixes:

- gpg: Fix wrong assertion failure which could very rarely occur
during key signature checking. [rG693f5642f6]

- gpg: Consider certify-only keys for revocation signature check.
[T8196]

- gpgsm: Fix possible double free in the CMS parser. [T8240]

- gpgsm: Fix possible too early removal of ephemeral keys. [T8236]

- gpgsm: Avoid emitting a final FAILURE status line if --status-fd
is not used. [rG69c27fe377]

- gpgsm: Fix a regression in 2.5.19 for password encrypted GCM
data. [rG60a823c97b]

- agent: Fix not using cache for pinentry loopback. [rGd4b608a31f]

- agent: Fix command PUT_SECRET by saving input line. [rG1875bc185e]

- keyboxd: Mark keys searched but not imported via LDAP correctly
as ephemeral. [T8048]

- scdaemon: Avoid buffer overflow with SC-HSM cards providing RSA
keys > 2k. [T8244]

- dirmngr: Fix uninitialized use of the dns_any union in
dns_rr_cmp. [T8251]

Release-info: https://dev.gnupg.org/T7997

infosec.exchange
2
0
2
0
Open post
FreePG Project @freepg@infosec.exchange
· 5mo ago

#GnuPG 2.2.53-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

In addition, a fix for the default filename path traversal issue identified by #gpgfail has been backported from upstream 2.5.16 (gpg.fail/filename)

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.2.53-freepg

infosec.exchange
2
0
0
0
Open post
FreePG Project @freepg@infosec.exchange
· 8mo ago

#GnuPG 2.5.17-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

* This release contains a fix for a critical buffer overflow vulnerability in GnuPG >= 2.5.13 - see upstream's release notes for full details.

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.17-freepg

infosec.exchange
4
0
5
0
Open post
FreePG Project @freepg@infosec.exchange
· 7mo ago

FreePG now has a public mailing list for general discussion and formal decision-making.

Thanks to simplelists.com for their kind sponsorship!

https://openpgp.simplelists.com/freepg

openpgp.simplelists.com
2
0
4
0
Open post
FreePG Project @freepg@infosec.exchange
· 9mo ago

#GnuPG 2.4.9-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

In addition, a fix for the default filename path traversal issue identified by #gpgfail has been backported from upstream 2.5.16 (https://gpg.fail/filename)

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.4.9-freepg

infosec.exchange
2
0
3
0
Open post
FreePG Project @freepg@infosec.exchange
· 9mo ago

#GnuPG 2.5.16-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.16-freepg

infosec.exchange
1
0
2
0
Open post
FreePG Project @freepg@infosec.exchange
· 5mo ago

#GnuPG 2.2.54-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

Release Notes
=============

## Noteworthy changes in version 2.2.54-freepg (2026-04-24)

* No FreePG-specific changes.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.2.54-freepg

Upstream's release notes follow.

-------------

## Noteworthy changes in version 2.2.54 (2026-04-20)

* gpg: Fix an edge case in --refresh-keys. [T8197]

* gpgsm: Add a certificate chain check for de-vs compliance.
[T8188]

* gpgsm: Show rsaPSS certificates as de-vs compliant in listings.
[T8222]

* agent: Accept a trustlist with a missing LF at the end. [T8078]

Release-info: https://dev.gnupg.org/T8170

infosec.exchange
0
0
1
0
Open post
FreePG Project @freepg@infosec.exchange
· 7mo ago

#GnuPG 2.5.18-freepg has been released.

It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

This release also contains fixes for additional gpg.fail issues that remain unfixed upstream:

* skip trust packets during import-restore (https://gpg.fail/trust)
* compat ignore truncated line (https://gpg.fail/formfeed)
* fail on unprintable armor headers (https://gpg.fail/nullbyte https://gpg.fail/notdash)

Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

https://gitlab.com/freepg/gnupg/-/releases/gnupg-2.5.18-freepg

infosec.exchange
0
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:41:30 UTC