Libgcrypt Vulnerability Affecting Signing Mechanism
CVE-2026-41990

4MEDIUM

Key Information:

Vendor

Gnupg

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-41990?

Libgcrypt, a cryptographic library maintained by GnuPG, has a vulnerability in its signing mechanism that affects versions prior to 1.12.2. The issue arises from improper handling of Dilithium signing, where a static array is written without adequate bounds checks. While the vulnerability does not utilize attacker-controlled data, it can still lead to unintended consequences in cryptographic operations, potentially compromising the integrity of signed data. Users are advised to update to the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

Libgcrypt 1.12.0 < 1.12.2

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.