Gnupg / Libgcrypt
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41990 | Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing. | MEDIUM | 4.0 | Apr 23, 2026 |
| CVE-2026-41989 | Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext | HIGH | 7.5 | Apr 23, 2026 |
| CVE-2021-40528 | libgcrypt: ElGamal implementation allows plaintext recovery | MEDIUM | 5.9 | Sep 6, 2021 |
| CVE-2021-33560 | libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm | HIGH | 7.5 | Jun 8, 2021 |
| CVE-2021-3345 | libgcrypt: Heap buffer overflow in the block buffer management code | CRITICAL | 9.8 | Jan 29, 2021 |
| CVE-2015-0837 | libgcrypt: last-level cache side-channel attack | MEDIUM | 5.9 | Nov 29, 2019 |
| CVE-2014-3591 | libgcrypt: use ciphertext blinding for Elgamal decryption (new side-channel attack) | MEDIUM | 4.2 | Nov 29, 2019 |
| CVE-2019-12904 | Libgcrypt: physical addresses being available to other processes leads to a flush-and-reload side-channel attack | MEDIUM | 5.9 | Jun 19, 2019 |
| CVE-2017-7526 | libgcrypt: Use of left-to-right sliding window method allows full RSA key recovery | MEDIUM | 6.8 | Jul 26, 2018 |
| CVE-2018-0495 | ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries | MEDIUM | 5.1 | Jun 13, 2018 |
| CVE-2018-6829 | libgcrypt: ElGamal implementation doesn't have semantic security due to incorrectly encoded plaintexts possibly allowing to obtain sensitive information | HIGH | 7.5 | Feb 7, 2018 |
| CVE-2017-0379 | libgcrypt: Missing input validation for X25519 curve | HIGH | 7.5 | Aug 29, 2017 |
| CVE-2017-9526 | libgcrypt: Possible timing attack on EdDSA session key | MEDIUM | 5.9 | Jun 11, 2017 |
| CVE-2016-6313 | libgcrypt: PRNG output is predictable | MEDIUM | 5.3 | Dec 13, 2016 |
| CVE-2015-7511 | libgcrypt: side-channel attack on ECDH with Weierstrass curves | LOW | 2.0 | Apr 19, 2016 |
| CVE-2014-5270 | libgcrypt: ELGAMAL side-channel attack | LOW | 2.1 | Oct 10, 2014 |
| CVE-2013-4242 | GnuPG susceptible to Yarom/Falkner flush+reload cache side-channel attack | LOW | 1.9 | Aug 19, 2013 |
Showing 1 to 17 of 17 CVEs