Packages
- gnupg2 - GNU privacy guard - a free PGP replacement
Details
USN-7412-1 fixed vulnerabilities in GnuPG. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that GnuPG incorrectly handled importing keys with
certain crafted subkey data. If a user or automated system were tricked
into importing a specially crafted key, a remote attacker may prevent
users from importing other keys in the future.
USN-7412-1 fixed vulnerabilities in GnuPG. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that GnuPG incorrectly handled importing keys with
certain crafted subkey data. If a user or automated system were tricked
into importing a specially crafted key, a remote attacker may prevent
users from importing other keys in the future.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 25.04 plucky | gnupg – 2.4.4-2ubuntu23.1 | ||
| gnupg2 – 2.4.4-2ubuntu23.1 | |||
| gpg – 2.4.4-2ubuntu23.1 | |||
| 24.10 oracular | gnupg – 2.4.4-2ubuntu18.3 | ||
| gnupg2 – 2.4.4-2ubuntu18.3 | |||
| gpg – 2.4.4-2ubuntu18.3 | |||
| 24.04 LTS noble | gnupg – 2.4.4-2ubuntu17.3 | ||
| gnupg2 – 2.4.4-2ubuntu17.3 | |||
| gpg – 2.4.4-2ubuntu17.3 | |||
| 22.04 LTS jammy | gnupg – 2.2.27-3ubuntu2.4 | ||
| gnupg2 – 2.2.27-3ubuntu2.4 | |||
| gpg – 2.2.27-3ubuntu2.4 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.