Home / mailings [USN-8720-1] GnuPG vulnerability
Posted on 03 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8720-1
September 03, 2026
gnupg2 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
Summary:
GnuPG could allow encrypted messages to be forged under certain
circumstances.
Software Description:
- gnupg2: GNU privacy guard - a free PGP replacement
Details:
It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
gpgsm 2.4.8-4ubuntu3.1
Ubuntu 24.04 LTS
gpgsm 2.4.4-2ubuntu17.6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8720-1
CVE-2026-57062
Package Information:
https://launchpad.net/ubuntu/+source/gnupg2/2.4.8-4ubuntu3.1
https://launchpad.net/ubuntu/+source/gnupg2/2.4.4-2ubuntu17.6
--===============3501557396523495567==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
