oss-sec mailing list archives
Re: Many vulnerabilities in GnuPG
From: Stephan Verbücheln <stephan () verbuecheln ch>
Date: Mon, 29 Dec 2025 10:15:29 +0100
GnuPG follows a traditional versioning scheme where even numbers (e.g. 2.2 and 2.4) are release branches and odd numbers (2.3 and 2.5) are developer branches. So what we have to wait for is 2.4.9 fixing the vulnerabilities. Alternatively, distributions will fix the critical ones independently. For instance, Debian 13 Trixie is using 2.4.7 and applies patches downstream. Regards
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Re: Many vulnerabilities in GnuPG, (continued)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 29)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 30)
- Re: Many vulnerabilities in GnuPG Henrik Ahlgren (Dec 30)
- Re: Many vulnerabilities in GnuPG Collin Funk (Dec 30)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 31)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 29)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 30)
- Re: Many vulnerabilities in GnuPG Jeffrey Walton (Dec 28)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 28)
- Re: Many vulnerabilities in GnuPG Stephan Verbücheln (Dec 29)
- Re: Many vulnerabilities in GnuPG Alan Coopersmith (Dec 30)
- Re: Many vulnerabilities in GnuPG Neal Gompa (Dec 29)
