Search CVE reports


Toggle filters

1 – 10 of 18 results


CVE-2026-41990

Medium priority
Fixed

Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

1 affected package

libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt20 Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-41989

Medium priority

Some fixes available 4 of 7

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

1 affected package

libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt20 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2024-2236

Low priority

Some fixes available 3 of 11

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

2 affected packages

libgcrypt11, libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt11 Not in release Not in release Not in release Not in release —
libgcrypt20 Fixed Fixed Fixed Vulnerable Vulnerable
Show less packages

CVE-2021-40528

Medium priority
Fixed

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the...

1 affected package

libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt20 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-33560

Low priority

Some fixes available 14 of 15

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example,...

1 affected package

libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt20 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-3345

High priority
Not affected

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

2 affected packages

libgcrypt11, libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt11 — — — Not in release Not in release
libgcrypt20 — — — Not affected Not affected
Show less packages

CVE-2019-13627

Medium priority
Fixed

It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

2 affected packages

libgcrypt11, libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt11 — — — — Not in release
libgcrypt20 — — — — Fixed
Show less packages

CVE-2019-12904

Low priority
Ignored

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an...

2 affected packages

libgcrypt11, libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt11 — — Not in release Not in release Not in release
libgcrypt20 — — Not affected Not affected Not affected
Show less packages

CVE-2018-0495

Low priority

Some fixes available 18 of 19

Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in...

6 affected packages

libgcrypt11, libgcrypt20, nss, openssl, openssl098, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgcrypt11 — — — — Not in release
libgcrypt20 — — — — Fixed
nss — — — — Fixed
openssl — — — — Fixed
openssl098 — — — — Not in release
openssl1.0 — — — — Fixed
Show less packages

CVE-2018-6829

Medium priority
Not affected

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic...

3 affected packages

gnupg, libgcrypt11, libgcrypt20

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnupg — — — — Not in release
libgcrypt11 — — — — Not in release
libgcrypt20 — — — — Not affected
Show less packages