Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing.
Published Apr 23, 2026
4.0
MEDIUMCVSS 3.1
EPSS 0.18%
Description
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
Affected products
-
- Version 1.12.0StatusaffectedConstraints<1.12.2
- Version
No data.
Red Hat Hardened Images
libgcrypt-main-1.12.2-1.hum1
Fixed · RHSA-2026:8466
Red Hat Enterprise Linux 10
libgcrypt
Fix deferred
Red Hat Enterprise Linux 10
thunderbird
Fix deferred
Red Hat Enterprise Linux 6
libgcrypt
Fix deferred
Red Hat Enterprise Linux 7
libgcrypt
Fix deferred
Red Hat Enterprise Linux 8
libgcrypt
Fix deferred
Red Hat Enterprise Linux 8
thunderbird
Fix deferred
Red Hat Enterprise Linux 9
libgcrypt
Fix deferred
Red Hat Enterprise Linux 9
thunderbird
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | libgcrypt-main-1.12.2-1.hum1 | Fixed | RHSA-2026:8466 |
| Red Hat Enterprise Linux 10 | libgcrypt | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | libgcrypt | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | libgcrypt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libgcrypt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | libgcrypt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-41990 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2461068 Issue Tracking
- https://dev.gnupg.org/T8208 Broken Link
- https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html Mailing ListRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-41990
- https://www.cve.org/CVERecord?id=CVE-2026-41990
- https://www.openwall.com/lists/oss-security/2026/04/21/1 Mailing ListRelease Notes
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41990 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2461068 | Issue Tracking | |
| https://dev.gnupg.org/T8208 | Broken Link | |
| https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html | Mailing ListRelease Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41990 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-41990 | ||
| https://www.openwall.com/lists/oss-security/2026/04/21/1 | Mailing ListRelease Notes |
Change history (0)
No recorded changes yet.