oss-sec mailing list archives
Retrospective by 'gpg.fail' authors
From: Sam James <sam () gentoo org>
Date: Sun, 13 Sep 2026 01:44:40 +0100
Hi, The authors of the 'gpg.fail' set of vulnerabilities have published a retrospective, previously discussed on this list [0]. A recording of the talk is available [1] as are slides [2]. They also mention another vulnerability in the slides that is in the talk but I've not seen that yet. A PoC is available in their repo [3]. (I've only made my way through the slides on an initial first pass, so I don't consider myself in a position to comment on the contents at this time.) [0] https://www.openwall.com/lists/oss-security/2025/12/28/1 [1] https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026 [2] https://git.gay/49016/gpg-fail-aftermath/raw/branch/main/slides.pd [3] https://git.gay/49016/gpg-fail-aftermath/src/branch/main/pocs sam
Attachment:
signature.asc
Description:
Current thread:
- Retrospective by 'gpg.fail' authors Sam James (Sep 12)
- Re: Retrospective by 'gpg.fail' authors Peter Gutmann (Sep 13)
