EXPOSURES › CVE-2026-24881
CVE-2026-24881
HIGH
DETAIL
SourceNVD · cve
Published2026-01-27
CVSS8.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-24881 ↗
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.