Home
MEDIUM: 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:LDefault status
unaffected
1.12.0 (semver) before 1.12.2
affected
Description
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
Problem types
Product status
1.12.0 (semver) before 1.12.2
References
lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html
www.openwall.com/lists/oss-security/2026/04/21/1