
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41990 is an out-of-bounds write vulnerability in Libgcrypt's Dilithium (post-quantum) signing implementation. Versions 1.12.0 through 1.12.1 are affected; the flaw was introduced with the Dilithium algorithm support added in version 1.12.0. The vulnerability was reported by Calif.io in collaboration with Claude and Anthropic Research, disclosed publicly on April 21, 2026 via the oss-security mailing list, and patched in Libgcrypt 1.12.2 (released April 15, 2026). It carries a CVSS v3.1 base score of 4.0 (Medium) (GitHub Advisory, Openwall).
The root cause is a missing bounds check (CWE-787: Out-of-bounds Write) on writes to a static array within the Dilithium signing context handling code in Libgcrypt. Critically, the out-of-bounds writes do not use attacker-controlled data — the values written are internally determined — which significantly limits exploitability. The attack vector is local, requires high attack complexity, and no privileges, meaning an attacker would need specific local conditions to trigger the flaw during a Dilithium signing operation. The bug was tracked internally as GnuPG issue T8208 (Openwall, GitHub Advisory).
Successful exploitation could result in limited integrity and availability impacts on the affected system; confidentiality is not impacted. Because the out-of-bounds write does not use attacker-controlled data, arbitrary code execution is unlikely, but memory corruption could cause crashes or unpredictable behavior in applications relying on Libgcrypt's Dilithium signing functionality. The scope is unchanged, meaning the impact is confined to the vulnerable component itself (GitHub Advisory, Openwall).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.012% (very low probability of exploitation within 30 days), and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. The high attack complexity and the fact that written data is not attacker-controlled further reduce practical exploitability (GitHub Advisory).
The primary remediation is to upgrade Libgcrypt to version 1.12.2 or later, which adds the missing bounds check to the Dilithium context handling. For systems that cannot immediately upgrade, restricting local user access to processes that perform Dilithium signing operations can reduce exposure. Ubuntu has issued security notice USN-8319-1 addressing this vulnerability. No configuration-based workaround is available as a substitute for patching (Openwall, Ubuntu Advisory).
The vulnerability was responsibly disclosed by Werner Koch (GnuPG maintainer) via the gnupg-announce and oss-security mailing lists. The discovery was credited to Calif.io in collaboration with Claude and Anthropic Research, marking a notable instance of AI-assisted security research contributing to an open-source cryptographic library fix. The Yocto Project security team also tracked and communicated the issue to their community via their security mailing list (Openwall).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
libgcrypt20
bionic (fips-updates)
libgcrypt20
bionic (fips)
libgcrypt20
devel
libgcrypt20
focal (esm-infra)
libgcrypt20
focal (fips-updates)
libgcrypt20
focal (fips)
libgcrypt20
jammy
libgcrypt20
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."