Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-41989
Libgcrypt vulnerability analysis and mitigation

Overview

CVE-2026-41989 is a heap-based buffer overflow vulnerability in Libgcrypt's ECDH decryption function (gcry_pk_decrypt) that can be triggered via crafted ECDH ciphertext, potentially leading to denial of service or heap corruption. It affects Libgcrypt versions 1.8.8 through 1.10.3, 1.11.0 through 1.11.2, and 1.12.0 through 1.12.1. The vulnerability was publicly disclosed on April 21, 2026, via the oss-security mailing list, with patched releases announced the same day by Werner Koch of the GnuPG project. It carries a CVSS v3.1 base score of 6.7 (Medium) (Github Advisory, oss-security).

Technical details

The root cause is an out-of-bounds write (CWE-787) — specifically, a possible buffer overwrite with zeroes during ECDH decryption processing in gcry_pk_decrypt. The flaw is triggered when the library processes specially crafted ECDH ciphertext using NIST, Brainpool, X448, or X25519 curves, causing data to be written beyond the allocated heap buffer boundaries. Exploitation requires local access and high attack complexity, as the attacker must be able to supply malicious ciphertext to the vulnerable decryption function. GnuPG versions since 2.5.7 are not affected because they use a different encryption API (oss-security, Github Advisory).

Impact

Successful exploitation can cause denial of service by crashing the application processing the crafted ECDH ciphertext, and may result in heap corruption that could potentially enable code execution or data manipulation. The integrity and availability impacts are rated High, while confidentiality is unaffected per the CVSS scoring. The vulnerability's local attack vector limits its reach, but any application or service relying on Libgcrypt for ECDH decryption — including cryptographic tools and secure communication software — is at risk (Github Advisory, oss-security).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The high attack complexity and local access requirement further reduce practical exploitability (Github Advisory).

Mitigation and workarounds

The GnuPG project has released patched versions addressing this vulnerability: Libgcrypt 1.12.2, 1.11.3, and 1.10.4. Version 1.12.2 is the recommended upgrade as it is fully compatible with all earlier versions. Organizations should prioritize upgrading all systems running affected versions (1.8.8–1.10.3, 1.11.0–1.11.2, or 1.12.0–1.12.1). As an interim measure, limiting local access to systems running vulnerable Libgcrypt versions can reduce exposure. Source tarballs are available from the GnuPG FTP server and mirrors (oss-security, Github Advisory).

Community reactions

The vulnerability was disclosed by Werner Koch of the GnuPG/g10 Code GmbH team via the gnupg-announce and oss-security mailing lists, with coordinated patched releases on April 21, 2026. The Yocto Project security list, Ubuntu (USN-8319-1), Amazon Linux (ALAS2023-2026-1705), Fedora, and Debian have all issued downstream advisories or updates. Tenable published multiple Nessus detection plugins (IDs 309928, 311104, 315026, 316550) shortly after disclosure, and the vulnerability was tracked by ENISA's EUVD database (oss-security, Ubuntu Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

libgcrypt20: 1.10.1-3+deb12u1

Fixed

sid

libgcrypt20: 1.12.2-1

Fixed

trixie

libgcrypt20: 1.11.0-7+deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

libgcrypt20

Unknown

bionic (fips-updates)

libgcrypt20

Unknown

bionic (fips)

libgcrypt20

Unknown

devel

libgcrypt20

Not Affected

focal (esm-infra)

libgcrypt20

Unknown

focal (fips-updates)

libgcrypt20

Unknown

focal (fips)

libgcrypt20

Unknown

jammy

libgcrypt20: 1.9.4-3ubuntu3.2

Fixed

RHEL / CentOS

Fixed

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

:baseos:libgcrypt-0:1.8.5-8.el8_10.src

Fixed

RHEL 9

:baseos:libgcrypt-0:1.10.0-10.el9_2.2.src

Fixed

RHEL 10

libgcrypt-0:1.11.0-5.el10_0.1.src

Fixed

SourceThis report was generated using AI

Related Libgcrypt vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-33560HIGH7.5
  • NixOS logoNixOS
  • libgcrypt11-32bit
NoYesJun 08, 2021
CVE-2026-41989MEDIUM6.7
  • Libgcrypt logoLibgcrypt
  • libgcrypt
NoYesApr 23, 2026
CVE-2024-2236MEDIUM5.9
  • Libgcrypt logoLibgcrypt
  • libgcrypt-debugsource
NoYesMar 06, 2024
CVE-2021-40528MEDIUM5.9
  • NixOS logoNixOS
  • kernel
NoYesSep 06, 2021
CVE-2026-41990MEDIUM4
  • Libgcrypt logoLibgcrypt
  • cpe:2.3:a:gnupg:libgcrypt
NoYesApr 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management