CVE-2025-30258
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Mar 19, 2025
CWE ID 754
Summary
CVE-2025-30258 is a vulnerability affecting GnuPG before version 2.5.5. By importing a certificate with specific subkey data, which may lack a valid backsig or have incorrect usage flags, users can experience a denial-of-service (DoS) when verifying signatures made from certain other signing keys. This issue prevents users from validating the authenticity of affected signatures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GNU Privacy Guard