[CLSA-2026:1785557084] gnupg2: Fix of CVE-2026-57062
Type:
security
Severity:
Moderate
Release date:
2026-08-01 04:04:59 UTC
Description:
- CVE-2026-57062: require a minimum AES-GCM authentication tag length of 12 octets in gpgsm CMS decryption; a 4-octet aes-ICVlen was previously accepted, weakening the integrity guarantee of the message
CVEs fixed:
Updated packages:
  • gnupg2-2.3.3-2.el9_0.tuxcare.els4.x86_64.rpm
    sha:d75466244fe1035c5f84be14e651ddc2425230228f3de348e1d44e58c70a39e2
  • gnupg2-smime-2.3.3-2.el9_0.tuxcare.els4.x86_64.rpm
    sha:fa6d23111d6e485c89361113755200ab5272a9151a041437164cff9fd3aec0d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.