Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68973

26
FAUCET Score

CVE-2025-68973 is a high-severity out-of-bounds write vulnerability affecting GnuPG versions prior to 2.4.9 (and ExtendedLTS versions before 2.2.51). This flaw, stemming from an incorrect index increment in the armor_filter function, could allow a local attacker to achieve high confidentiality, integrity, and availability impacts through crafted input. Despite its high CVSS score of 7.0, there is currently no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2.2.51CPE match
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
>= 2.3.0, < 2.4.9CPE match
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
<= 2.4.8CPE matchmatch criteria
cpe:2.3:a:gnupg:gnupg:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.4
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 13th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (62)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 20333-17084Fixed in: 2.4.9-1
microsoftpatch availablevia msrc
Product: 20331-17086Fixed in: 2.4.0-3
microsoftpatch availablevia msrc
Product: azl3 gnupg2 2.4.7-1 on Azure Linux 3.0Fixed in: 2.4.9-1
microsoftpatch availablevia msrc
Product: cbl2 gnupg2 2.4.0-2 on CBL Mariner 2.0Fixed in: 2.4.0-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: gnupg2-0:2.2.9-1.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: gnupg2-0:2.2.20-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: gnupg2-0:2.2.20-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: gnupg2-0:2.2.20-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: gnupg2-0:2.2.20-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: gnupg2-0:2.2.20-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: gnupg2-0:2.2.20-3.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: gnupg2-0:2.2.20-3.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gnupg2-0:2.3.3-5.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: gnupg2-0:2.3.3-2.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: gnupg2-0:2.3.3-2.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: gnupg2-0:2.3.3-4.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: gnupg2-0:2.3.3-4.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-content-rhel8:sha256:c3be1b6c7f4a941ea8ce04911a6ad4e131d68edaf740202edd3d8e81a5ada121
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-must-gather-rhel8:sha256:b28e5ae6585ee33cbe4b18240dc05654c97960174beafca7575e9e0e452f7fb0
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-openscap-rhel8:sha256:381e2f4b0aa56ebe408bb4a7b75edbc2b67ad972df8435ad4207b631c58b6047
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-rhel8-operator:sha256:b91a28de45761e8aa69752b0120cfa9cbfa1eb9bdd291ab77241e2b23d15c5e2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:sha256:eaea088de3ff04166ec467b67d70f55662a2917441d3d9d4e8dd39677031bc4c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-collector-rhel8:sha256:5271f61b08c3c593db3285d7d68014792440944ee38c2fff1839f2d401cc27ad
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:f96217aeff1a39024700537986dca70ce7e94949c91c3da815dc715ef6588044
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-rhel8-operator:sha256:194bed8ce4509622b1802b5b6c528e34c4fa610e7ca2894d2c5a34874e1e393f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8:sha256:dcfa45646e951547da04021f3f35d7262a95f565366a1c5ebbf12532f783f686
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:sha256:9386cdac44378229ee4bbae348924e496738eadbb30a5a338886280a5361c91a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-scanner-rhel8:sha256:5180c88b2677bb366aea5af964bf40c1bad8bbf4c33cefaba87ce6c22e9e8e17
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:1a3802e374386dd277f1e806a0cc7cdd9327dd57900df2e8af373acb0501a862
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:1c5cb619fc844a48f79d2996d8c2239bab7077845d404184515d4e7df7afdc6e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:sha256:294c8f3d3cce71c22e6bde11783c04fa5db2ae19ad2a741c418005faa41da67a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-collector-rhel8:sha256:32faefcdb174ed2e92291cc075ab321e8fa462fcbd951e7edaa019011e87ccad
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:01d01a649ed0c466925ebdfc7e632c7c01f0e59ef5d764d2f2dcf51f355b68ec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-rhel8-operator:sha256:6f0060cfb71c9ee2788f2bcebd1d9aa40e337c10921a4c631c0119c80721b539
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8:sha256:96ba7c71703db09c15f1633d2b5c14a22231a6f87fffacb639542f4ad2429551
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:sha256:e2d7323de0313fc7e498791d2294fe4c46448638753349002dfa0e16580f9435
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-rhel8:sha256:bd07e7aa5ab8f4419cfe29872bc99d6bca1fe5c73034633ec371b1f1ff59d66c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:6772a5c3a85b279176346e893e3ed08498861ee31495c32236dab20a95392871
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:9848a4f71fd2bfdc2a22a338a253875f3073777c0d5d5f70b88429d8d4459fdf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:sha256:883829bc4863879bfa6f1a73b18a7dca659a699664a3851f24e2b08cc15cf0e0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-collector-rhel8:sha256:6ddaad689e2065044d8c13fed306f0d6051199b19689b12c4d60c785243cb3ee
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:25bb4a371c5656d01a53060df46b7fbb5a287fe843c08581be69fb42ff5ec5dd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-rhel8-operator:sha256:9fd9a15845c8e2b663c502a15efb17f2bc3b3555eb513a7972ffe71f37654b9e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8:sha256:7a49b9e8ea59229abd9c73c7c0c89ca4e6ed4b30ff8c3b5867c7aaf861658bf2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:sha256:05ddda7a4ba49a18e5498d9ff8c3565f7a4abc96c985feec10887bb0c1b8aec3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-rhel8:sha256:5f83884b0a2b48f34e14b949f43e68ad4b99cb8d228bec74b5126b89cc007808
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-v4-db-rhel8:sha256:ec5aa99bc9c1fdc57be287f9402cbcdd31274eeac7bc158615c0c61a9fa7f3fe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-scanner-v4-rhel8:sha256:b57d042b045f2600dbd6e446c0c651b1ae0a85158077bd52cd0b76616bb95230
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:7c82e63b4db275f455ef10b251a8093611ad07898386aaf01faad687b461b5d4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:97a60239048123bc963d7c9ac2ad85caa6a254759e44c15f173ca12ea51e4719
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:519d4fe184cebe5152f840e9f609fa4705590656ac9bcace2e2e17622ab7e6a8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:26bb49a8e2e695d61192f04eb0db63efa8210bba20ea22b60e4e22d519d8b9e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:ab86ba36e62e8aec5ba48e9e0076b1f8086c48157c85990be0e2ce3e03273016
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/haproxy-rhel9:sha256:409a64405669fd11ad8700356243762a3507430f9bba4100bb92765d4482b7e5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/rhua-rhel9:sha256:df709663b581b740006c6ea4b297978932874eade1563c3952e0594e926aa5f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/cds-rhel9:sha256:83e8b356eb4697a81ff8c6764dc976862800f4c78122a606173340a6e105a4fe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: gnupg2-0:2.4.5-3.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: gnupg2-0:2.4.5-2.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: gnupg2-0:2.0.22-5.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnupg2-0:2.2.20-4.el8_10
View patch

Vendor Advisories (2)

redhatCVE-2025-68973Important

GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

Dec 28, 2025
microsoft2025-Dec/CVE-2025-68973Important

In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

Dec 9, 2025

References

lists.debian.org / debian-lts-announce/2026/01/msg00008.html
openwall.com / lists/oss-security/2025/12/29/11
Mailing ListPatch
github.com / gpg/gnupg/blob/ff30683418695f5d2cc9e6cf8c9418e09378ebe4/g10/armor.c
Product
github.com / gpg/gnupg/commit/115d138ba599328005c5321c0ef9f00355838ca9
Patch
github.com / gpg/gnupg/compare/gnupg-2.2.50...gnupg-2.2.51
Patch
gpg.fail / memcpy
Broken Link
media.ccc.de / v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i
Issue Tracking
news.ycombinator.com / item
Issue Tracking
openwall.com / lists/oss-security/2025/12/28/5
Mailing List