USN-8720-1: GnuPG vulnerability

Publication date

3 September 2026

Overview

GnuPG could allow encrypted messages to be forged under certain circumstances.


Packages

  • gnupg2 - GNU privacy guard - a free PGP replacement

Details

It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.

It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute gpgsm –  2.4.8-4ubuntu3.1
24.04 LTS noble gpgsm –  2.4.4-2ubuntu17.6

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›