GnuPG: Arbitrary Code Execution — GLSA 202512-01

A vulnerability has been discovered in GnuPG, which can lead to arbitrary code execution.

Affected packages

app-crypt/gnupg on all architectures
Affected versions < 2.5.14
Unaffected versions >= 2.5.14

Background

The GNU Privacy Guard, GnuPG, is a free replacement for the PGP suite of cryptographic software.

Description

A vulnerability has been discovered in GnuPG's armor parser.

Impact

A remote attacker could entice a user or automated system to process a specially crafted signature file, possibly resulting in execution of arbitrary commands with the privileges of the process.

Workaround

There is no known workaround at this time.

Resolution

All GnuPG users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-crypt/gnupg-2.5.14"
 

References

Release date
December 27, 2025

Latest revision
December 27, 2025: 1

Severity
high

Exploitable
remote

Bugzilla entries