Executive brief
GnuPG is a widely used encryption suite for securing emails and files. A vulnerability in its S/MIME handling allows an attacker to send a specially crafted encrypted message that crashes the background service responsible for managing private keys. In some scenarios, this could allow an attacker to gain unauthorized control over the system or disrupt secure communications.
Technical details
A stack-based buffer overflow exists in gpg-agent's agent_kem_decrypt() function when processing PKDECRYPT --kem=CMS requests. The vulnerability is caused by trusting an attacker-supplied length for a wrapped session key, which is then used to perform an AES Key Wrap unwrap into a fixed 256-byte stack buffer. Because libgcrypt's AES-KW implementation performs a memmove of the ciphertext into the output buffer before verifying integrity, the overflow occurs even if the message is otherwise invalid. This affects GnuPG versions 2.5.13 through 2.5.16 and was fixed in version 2.5.17. An attacker can trigger this remotely by sending a malicious S/MIME message to a user.
Affected products
- GnuPG GnuPG 2.5.13 to 2.5.16
- Gpg4win Gpg4win 5.0.0
Timeline
- 2026-01-18: disclosed: Reported to GnuPG by OpenAI Security Research
- 2026-01-27: patched: GnuPG 2.5.17 released
- 2026-01-27: advisory