#VU120610 Numeric truncation error in GnuPG - CVE-2025-68972
Published: December 29, 2025
GnuPG
GNU
Description
The vulnerability allows a remote attacker to spoof contents of signed messages.
The vulnerability exists due to software truncates plaintext lines to 20000 characters minus padding when verifying signed data. A remote attacker can inject arbitrary payload into signed messages that still could be verified, allowing message spoofing.