← Back

CVE-2025-68972

nvd nist
Published: Dec 27, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.7
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.0 / Impact: 3.6
Source: NVD

Description

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

Affected (1)

Products: Gnupg: Gnupg
1 product
Gnupg
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.4.8

References (4)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Issue Tracking
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Product

Timeline

No history available yet.