Description
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
Published: 2026-06-23
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title GnuPG: Incorrect cryptographic message parsing
References
Metrics threat_severity

None

threat_severity

Low


Wed, 24 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Title GnuPG gpgsm AES‑GCM ICV Length Handling Improperly Validated

Wed, 24 Jun 2026 07:15:00 +0000

Type Values Removed Values Added
Title GnuPG gpgsm AES‑GCM ICV Length Handling Improperly Validated

Wed, 24 Jun 2026 04:30:00 +0000

Type Values Removed Values Added
Title Incorrect AES‑GCM ICV Length Handling in GnuPG CMS Parsing

Wed, 24 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
Title Incorrect AES‑GCM ICV Length Handling in GnuPG CMS Parsing

Tue, 23 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title CMS Parser Accepts Invalid AES‑GCM ICV Length in GnuPG gpgsm

Tue, 23 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title CMS Parser Accepts Invalid AES‑GCM ICV Length in GnuPG gpgsm

Tue, 23 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Description CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
First Time appeared Gnupg
Gnupg gnupg
Weaknesses CWE-1284
CPEs cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
Vendors & Products Gnupg
Gnupg gnupg
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-23T17:35:30.113Z

Reserved: 2026-06-23T17:26:24.801Z

Link: CVE-2026-57062

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-06-23T17:26:25Z

Links: CVE-2026-57062 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T13:15:15Z

Weaknesses