oss-sec mailing list archives

Retrospective by 'gpg.fail' authors


From: Sam James <sam () gentoo org>
Date: Sun, 13 Sep 2026 01:44:40 +0100

Hi,

The authors of the 'gpg.fail' set of vulnerabilities have published a
retrospective, previously discussed on this list [0].

A recording of the talk is available [1] as are slides [2].

They also mention another vulnerability in the slides that is in the
talk but I've not seen that yet. A PoC is available in their repo [3].

(I've only made my way through the slides on an initial first pass, so I
don't consider myself in a position to comment on the contents at this
time.)

[0] https://www.openwall.com/lists/oss-security/2025/12/28/1
[1] 
https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026
[2] https://git.gay/49016/gpg-fail-aftermath/raw/branch/main/slides.pd
[3] https://git.gay/49016/gpg-fail-aftermath/src/branch/main/pocs

sam

Attachment: signature.asc
Description:


Current thread: