In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
History

Tue, 30 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
Title gnupg: GnuPG: Signature bypass via form feed character in signed messages
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 29 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 27 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnupg
Gnupg gnupg
CPEs cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
Vendors & Products Gnupg
Gnupg gnupg

Sat, 27 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-29T16:51:02.621Z

Reserved: 2025-12-27T22:52:30.688Z

Link: CVE-2025-68972

cve-icon Vulnrichment

Updated: 2025-12-29T16:42:59.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-27T23:15:40.900

Modified: 2025-12-29T17:15:47.977

Link: CVE-2025-68972

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-27T22:52:30Z

Links: CVE-2025-68972 - Bugzilla