CVE-2025-68972 - CVE House
Back to Database
Status published Medium CVE-2025-68972

In GnuPG through 2.4.8, if a signed message has \f...

Vulnerability Description

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68972

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

GnuPG
Vulnerable Versions:
0

Timeline

Official Publish: December 27th, 2025
Last Modified: January 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Weaknesses (CWE)