CVE-2026-57062LowCVSS 2.9
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
🔗 CVE IDs covered (1)
🎯 Affected products2
- azl3 gnupg2 2.4.9-2 on Azure Linux 3.0
- azl3 gnupg2 2.4.9-3 on Azure Linux 3.0
✅ Remediation
KBCBL-Mariner Releases (Security Update) — fixed build 2.4.9-3