It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity checks.
USN-8720-1: GnuPG vulnerability
calendar_today
September 3, 2026
domain
ubuntu