Skip to content
COOEY

EXPOSURES › CVE-2026-24881

CVE-2026-24881

HIGH
DETAIL
SourceNVD · cve Published2026-01-27 CVSS8.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-24881 ↗

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.