Page MenuHome GnuPG
Feed Advanced Search

Mon, Feb 2

ikloecker created T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong.
Mon, Feb 2, 4:32 PM · gpd5x, Bug Report, kleopatra
werner triaged T8078: GpgAgent: trustlist.txt still requires LF on the last line as Low priority.

Oh yeah, the mentioned patch is bogus because it assumes that fgets has already set the eof flag while reading the last line. This seems not to be the case.

Mon, Feb 2, 3:46 PM · Bug Report, gpgagent, gnupg26
timegrid created T8078: GpgAgent: trustlist.txt still requires LF on the last line.
Mon, Feb 2, 3:20 PM · Bug Report, gpgagent, gnupg26
werner triaged T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key as Normal priority.
Mon, Feb 2, 12:08 PM · gnupg26, gpd5x, kleopatra, Bug Report
ebo added a project to T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key: gpd5x.
Mon, Feb 2, 11:53 AM · gnupg26, gpd5x, kleopatra, Bug Report
ikloecker renamed T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key from Kleopatra: Unable to completely delete incomplete team key to Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key.
Mon, Feb 2, 11:49 AM · gnupg26, gpd5x, kleopatra, Bug Report
ikloecker added a comment to T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key.

This is actually a (known) bug in gpg, i.e. gpg --delete-secret-and-public-key PRIMARY_KEY_FPR only deletes the public key for keys without primary secret key.

Mon, Feb 2, 11:39 AM · gnupg26, gpd5x, kleopatra, Bug Report
ikloecker created T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key.
Mon, Feb 2, 11:27 AM · gnupg26, gpd5x, kleopatra, Bug Report
ikloecker closed T8070: qgpgme-2.0.0: Solaris (SmartOS) build problem as Resolved.

Makes me wonder why they think they can use such a common word for a typedef without risking name clashes everywhere. Luckily, the helper function single is superfluous nowadays so that we can easily avoid the name clash.

Mon, Feb 2, 10:58 AM · Solaris, gpgmeqt, Bug Report
ikloecker triaged T8070: qgpgme-2.0.0: Solaris (SmartOS) build problem as Normal priority.
Mon, Feb 2, 10:54 AM · Solaris, gpgmeqt, Bug Report
ebo moved T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings" from Backlog to WIP on the gpd5x board.
Mon, Feb 2, 10:19 AM · vsd33 (vsd-3.3.5), Bug Report, gpd5x, gpgol
gniibe added a comment to T8065: gnupg self test hang: clean migration.

Thank you for the log.

Mon, Feb 2, 8:14 AM · gpgrt, NetBSD, gnupg26, Bug Report

Sun, Feb 1

ametzler1 added a comment to T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`.

CVE-2026-24882 has been assigned to this issue.

Sun, Feb 1, 4:45 PM · gnupg26, CVE, TPM, Bug Report
werner added projects to T8071: libgrcypt 1.12.0: SmartOS (Solaris) build problem: Bug Report, Solaris.
Sun, Feb 1, 2:13 PM · Solaris, Bug Report, libgcrypt

Sat, Jan 31

wiz created T8070: qgpgme-2.0.0: Solaris (SmartOS) build problem.
Sat, Jan 31, 6:44 PM · Solaris, gpgmeqt, Bug Report

Fri, Jan 30

timegrid added a comment to T8052: GnuPG: First listing of secret keys is empty.

I added the gpgsm log output (same error as in the gpg log)

Fri, Jan 30, 11:25 AM · gpgrt, Bug Report, gpgagent, gpd5x, gnupg26
timegrid updated the task description for T8052: GnuPG: First listing of secret keys is empty.
Fri, Jan 30, 11:24 AM · gpgrt, Bug Report, gpgagent, gpd5x, gnupg26
timegrid closed T8053: GpgSM: `log-file` is ignored as Invalid.

Ah, thanks for the pointer, I did not expect gpgsm to behave differently here. Then it's probably intentional and I'll close this as invalid.

Fri, Jan 30, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26
pl13 added a comment to T8053: GpgSM: `log-file` is ignored.

The gnupg manual (page 113) mentions:

Fri, Jan 30, 10:30 AM · gpd5x, Bug Report, S/MIME, gnupg26
wiz added a comment to T8065: gnupg self test hang: clean migration.

Thank you for looking at this.
I'm testing with gnupg git head as of today, please let me know if you prefer 2.5.17 instead.

Fri, Jan 30, 9:46 AM · gpgrt, NetBSD, gnupg26, Bug Report
gniibe claimed T8065: gnupg self test hang: clean migration.
Fri, Jan 30, 9:02 AM · gpgrt, NetBSD, gnupg26, Bug Report
gniibe added a comment to T8065: gnupg self test hang: clean migration.

Thank you for your report.

Fri, Jan 30, 9:00 AM · gpgrt, NetBSD, gnupg26, Bug Report

Thu, Jan 29

ebo closed T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings" as Resolved.
Thu, Jan 29, 5:44 PM · vsd33 (vsd-3.3.5), Bug Report, gpd5x, gpgol
ebo moved T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings" from Triage to Done on the gpgol board.

works in vsd 3.3.5

Thu, Jan 29, 5:44 PM · vsd33 (vsd-3.3.5), Bug Report, gpd5x, gpgol
timegrid moved T6425: improve pinentry behavior and texts in smart card context from Backlog to QA on the gpd5x board.
Thu, Jan 29, 3:49 PM · gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report
timegrid edited projects for T6425: improve pinentry behavior and texts in smart card context , added: gpd5x; removed Restricted Project.
Thu, Jan 29, 3:49 PM · gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report
werner closed T7226: libgcrypt 1.11.0 buid error on armhf with gcc-14 as Resolved.
Thu, Jan 29, 2:21 PM · FTBFS, arm, libgcrypt, Bug Report
werner closed T7220: The CF protection not enabled in libgcrypt as Resolved.
Thu, Jan 29, 2:20 PM · libgcrypt, Bug Report
werner closed T7519: libgcrypt: (EC)DSA signature generation should be constant-time as Resolved.
Thu, Jan 29, 2:20 PM · libgcrypt, Bug Report
werner closed T7889: libgcrypt: HAVE_BROKEN_MLOCK as Resolved.
Thu, Jan 29, 2:19 PM · backport, libgcrypt, Bug Report
wiz added a comment to T8065: gnupg self test hang: clean migration.

I bisected it and found the commit that introduced this test failure:

Thu, Jan 29, 2:07 PM · gpgrt, NetBSD, gnupg26, Bug Report
ebo updated subscribers of T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings".

@mmontkowski, use this as string:

Thu, Jan 29, 1:56 PM · vsd33 (vsd-3.3.5), Bug Report, gpd5x, gpgol
wiz added a comment to T8065: gnupg self test hang: clean migration.

In the same environment, 2.4.9 passes its self tests.
I've reverted the update in pkgsrc until this can be resolved.

Thu, Jan 29, 8:56 AM · gpgrt, NetBSD, gnupg26, Bug Report
gniibe created T8066: gpgrt: Static linking support.
Thu, Jan 29, 5:21 AM · Linux, Feature Request, gpgrt

Wed, Jan 28

wiz added a comment to T8065: gnupg self test hang: clean migration.

The previous pkgsrc version was 2.4.9. However, I've just tested 2.5.14 and saw the same behaviour (so I guess there is no point in testing 2.5.16).

Wed, Jan 28, 5:17 PM · gpgrt, NetBSD, gnupg26, Bug Report
ebo added a project to T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings": Bug Report.
Wed, Jan 28, 4:56 PM · vsd33 (vsd-3.3.5), Bug Report, gpd5x, gpgol
werner added projects to T8065: gnupg self test hang: clean migration: gnupg26, NetBSD.

Do you remember wether you had the same problem also with 2.5.14 or 2.5.16? Or can you test with these versions? Which version of libgpg-error are you using?

Wed, Jan 28, 4:13 PM · gpgrt, NetBSD, gnupg26, Bug Report
wiz added a comment to T8065: gnupg self test hang: clean migration.

When I kill the gpg process, I see:

("/tmp/security/gnupg2/work/gnupg-2.5.17/g10/gpg" --no-permission-warning --no-greeting --no-secmem-warning --batch "--agent-program=/tmp/security/gnupg2/work/gnupg-2.5.17/agent/gpg-agent|--debug-quick-random" --list-sec
ret-keys) failed: gpg: starting migration from earlier GnuPG versions
Wed, Jan 28, 3:57 PM · gpgrt, NetBSD, gnupg26, Bug Report
wiz updated the task description for T8065: gnupg self test hang: clean migration.
Wed, Jan 28, 3:52 PM · gpgrt, NetBSD, gnupg26, Bug Report
wiz created T8065: gnupg self test hang: clean migration.
Wed, Jan 28, 3:52 PM · gpgrt, NetBSD, gnupg26, Bug Report
werner added a comment to T8029: IPC error on batch import of secret kyber cert.

My actual plan is to rework the imp[ort/export of secret keys to gpg-agent. Right now gpg-agent has knowledge of OpenPGP for import/export. This is not good and the required conversion should be moved to a helper tools for easier testing and to have this out of the gpg-agent process. For Kyber we right now don't use any conversion mut store the secret keys in gpg-agent's native format. Thus the passphrase is not necessary. We need to figure out why we have this problem here.

Wed, Jan 28, 11:47 AM · gnupg26, Bug Report, gpd5x, kleopatra

Tue, Jan 27

werner closed T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` as Resolved.
Tue, Jan 27, 5:18 PM · gnupg26, CVE, TPM, Bug Report
werner closed T8049: Null pointer dereference with overlong signature packet as Resolved.
Tue, Jan 27, 5:17 PM · segv, gnupg26, Bug Report
werner closed T8055: pinentry-tty: Correct/Cancel/Wrong - what does "C" select? as Resolved.
Tue, Jan 27, 5:17 PM · gnupg, pinentry, Bug Report
werner renamed T8049: Null pointer dereference with overlong signature packet from Security (internal) - Aisle Research report: Null pointer dereference with overlong signature packet to Null pointer dereference with overlong signature packet.
Tue, Jan 27, 5:16 PM · segv, gnupg26, Bug Report
werner changed the visibility for T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`.
Tue, Jan 27, 5:12 PM · gnupg26, CVE, TPM, Bug Report
werner closed T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM as Resolved.
Tue, Jan 27, 5:12 PM · CVE, gnupg26, gpgagent, Bug Report
ebo moved T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from Backlog to Done on the gnupg26 board.
Tue, Jan 27, 2:34 PM · gnupg26, CVE, TPM, Bug Report
ebo edited projects for T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`, added: gnupg26; removed gnupg.
Tue, Jan 27, 2:33 PM · gnupg26, CVE, TPM, Bug Report
ebo moved T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Backlog to Done on the gnupg26 board.
Tue, Jan 27, 2:31 PM · CVE, gnupg26, gpgagent, Bug Report
ebo moved T4581: Kleopatra stuck in loading the certificate cache from Done to gpd-5.0.0 on the gpd5x board.
Tue, Jan 27, 1:59 PM · gpd5x (gpd-5.0.0), gpg4win, kleopatra, Bug Report
ebo moved T8026: Kleopatra: Export of multiple S/MIME certificates only exports one from Done to gpd-5.0.1 on the gpd5x board.
Tue, Jan 27, 1:58 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report
ebo closed T8026: Kleopatra: Export of multiple S/MIME certificates only exports one as Resolved.
Tue, Jan 27, 1:54 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report
ebo moved T8026: Kleopatra: Export of multiple S/MIME certificates only exports one from WIP to Done on the gnupg26 board.

works in Gpg4win 5.0.1 with GnuPG 2.5.17

Tue, Jan 27, 1:52 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report

Mon, Jan 26

timegrid added a comment to T8052: GnuPG: First listing of secret keys is empty.

To reproduce the hang, a loop will suffice (usually happens within the first 15 times, once it needed 50 runs):

Mon, Jan 26, 11:39 AM · gpgrt, Bug Report, gpgagent, gpd5x, gnupg26
timegrid added a comment to T8053: GpgSM: `log-file` is ignored.

There's no other configuration, this happens with a clean gnupghome with one smime cert + root cert and the above gpgsm.conf (output on stdin/stderr):

Mon, Jan 26, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26

Sun, Jan 25

werner added a comment to T8049: Null pointer dereference with overlong signature packet.

Reconsidering this all I don't think it makes any sense to distinguish between (-1) and GPG_ERR_INV_PACKET. We use (-1) for a too short read of the hashed or unhashed area (premature eof). INV_PACKET is for unknown versions, too much data (arbitrary limit), bad parameters, and underflow. Let's forget my previous comment and always use INV_PACKET.

Sun, Jan 25, 5:23 PM · segv, gnupg26, Bug Report
werner changed the status of T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from Open to Testing.
Sun, Jan 25, 5:02 PM · gnupg26, CVE, TPM, Bug Report
werner triaged T8055: pinentry-tty: Correct/Cancel/Wrong - what does "C" select? as Low priority.
Sun, Jan 25, 4:38 PM · gnupg, pinentry, Bug Report
werner added a comment to T8055: pinentry-tty: Correct/Cancel/Wrong - what does "C" select?.

I think "O" is a better key:

Sun, Jan 25, 4:37 PM · gnupg, pinentry, Bug Report
werner added a comment to T8055: pinentry-tty: Correct/Cancel/Wrong - what does "C" select?.

We need to change the accelerator. Right now gpg-agent uses

Sun, Jan 25, 4:14 PM · gnupg, pinentry, Bug Report
ametzler1 created T8055: pinentry-tty: Correct/Cancel/Wrong - what does "C" select?.
Sun, Jan 25, 7:47 AM · gnupg, pinentry, Bug Report

Fri, Jan 23

werner lowered the priority of T8049: Null pointer dereference with overlong signature packet from Unbreak Now! to Normal.
Fri, Jan 23, 9:18 PM · segv, gnupg26, Bug Report
werner added a comment to T8053: GpgSM: `log-file` is ignored.

Please run with --debug 0 which should show you which confiration files are read in which order. Is there anything in a common.conf file? A log-file statement tehre would overwrite the command line option.

Fri, Jan 23, 9:16 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid updated the task description for T8052: GnuPG: First listing of secret keys is empty.
Fri, Jan 23, 2:43 PM · gpgrt, Bug Report, gpgagent, gpd5x, gnupg26
timegrid created T8053: GpgSM: `log-file` is ignored.
Fri, Jan 23, 2:28 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid added a project to T8052: GnuPG: First listing of secret keys is empty: Bug Report.
Fri, Jan 23, 2:22 PM · gpgrt, Bug Report, gpgagent, gpd5x, gnupg26
timegrid added a project to T6767: Kleopatra: system error without error code when encrypting a file to full disk on Windows: Bug Report.
Fri, Jan 23, 11:12 AM · Bug Report, gpd5x, gpgme, kleopatra

Thu, Jan 22

ikloecker changed the status of T8051: Kleopatra: Tab navigation in smartcard table is broken from Open to Testing.

Fixed and backported for VSD 3.4

Thu, Jan 22, 5:06 PM · Bug Report, vsd34, a11y, gpd5x, kleopatra
ikloecker moved T8051: Kleopatra: Tab navigation in smartcard table is broken from Backlog to WIP on the gpd5x board.
Thu, Jan 22, 5:03 PM · Bug Report, vsd34, a11y, gpd5x, kleopatra
ikloecker renamed T8051: Kleopatra: Tab navigation in smartcard table is broken from Kleopatra: Fix tab navigation in smart card table to Kleopatra: Tab navigation in smartcard table is broken.
Thu, Jan 22, 3:19 PM · Bug Report, vsd34, a11y, gpd5x, kleopatra
gniibe added a comment to T8049: Null pointer dereference with overlong signature packet.

Here are changes to fix the behavior:


Thu, Jan 22, 7:48 AM · segv, gnupg26, Bug Report
gniibe renamed T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from Security (internal) - Stack-based buffer overflow in TPM2 `PKDECRYPT` to Stack-based buffer overflow in TPM2 `PKDECRYPT`.
Thu, Jan 22, 12:33 AM · gnupg26, CVE, TPM, Bug Report

Wed, Jan 21

werner shifted T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from the Restricted Space space to the S1 Public space.
Wed, Jan 21, 12:40 PM · gnupg26, CVE, TPM, Bug Report
werner shifted T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from the Restricted Space space to the S1 Public space.
Wed, Jan 21, 12:23 PM · CVE, gnupg26, gpgagent, Bug Report
TobiasFella placed T7644: Kleopatra: 'Show Audit Log' in signature verification needs two clicks to open up for grabs.
Wed, Jan 21, 11:12 AM · gpd5x (gpd-5.0.0), vsd34, Bug Report, kleopatra
TobiasFella closed T7429: Kleopatra: Importing certificate from Verification result dialog doesn't correctly re-verify the signature as Resolved.
Wed, Jan 21, 11:06 AM · gpd5x (gpd-5.0.0), kleopatra, Bug Report
werner closed T8032: libksba: Input validation for DER encoded INTEGER as Wontfix.
Wed, Jan 21, 10:39 AM · S/MIME, libksba, Bug Report
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

The "ca" root cert is not on the ldap, if that matters

Wed, Jan 21, 10:23 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
werner changed the status of T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Open to Testing.
Wed, Jan 21, 10:20 AM · CVE, gnupg26, gpgagent, Bug Report
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from GnuPG: S/MIME certificate is imported on ldap search to Keyboxd: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:14 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

some other certificates, but I guess those are from other tests

Wed, Jan 21, 10:08 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a project to T8048: Keyboxd: S/MIME certificate is imported on ldap search: Bug Report.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
gniibe created T8049: Null pointer dereference with overlong signature packet.
Wed, Jan 21, 7:57 AM · segv, gnupg26, Bug Report

Tue, Jan 20

timegrid moved T7429: Kleopatra: Importing certificate from Verification result dialog doesn't correctly re-verify the signature from Done to gpd-5.0.0 on the gpd5x board.
Tue, Jan 20, 3:33 PM · gpd5x (gpd-5.0.0), kleopatra, Bug Report
werner claimed T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM.
Tue, Jan 20, 2:44 PM · CVE, gnupg26, gpgagent, Bug Report
ikloecker changed the status of T7789: Kleopatra: Wrong error message when choosing an expired certificate for encryption from Open to Testing.

Fixed and backported for VSD 3.4

Tue, Jan 20, 2:19 PM · vsd34, Bug Report, gpd5x, kleopatra
werner added a comment to T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM.

I have this fix committed to my working directory:

Tue, Jan 20, 12:54 PM · CVE, gnupg26, gpgagent, Bug Report
werner added a project to T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM: CVE.

We have no CVE yet. However, CVE is also a good tag for security bugs,

Tue, Jan 20, 12:18 PM · CVE, gnupg26, gpgagent, Bug Report
werner renamed T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Security (internal) - gpg-agent stack buffer overflow to gpg-agent stack buffer overflow in pkdecrypt using KEM.
Tue, Jan 20, 12:10 PM · CVE, gnupg26, gpgagent, Bug Report

Jan 20 2026

gniibe added a comment to T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM.

On 2026-01-20, I found the message to security@gnupg.org of:
Message-ID: 4e708880-04ac-45bc-8d16-6b585f2652a1n@aisle.com
in may spam folder. It has a 10MB long attachment. That might be one of reasons to be identified as a spam.

Jan 20 2026, 6:42 AM · CVE, gnupg26, gpgagent, Bug Report
gniibe added a comment to T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`.

Considering the current implementation (tpm2d doesn't support keyinfo like scdaemon), it would be good to check the buffer size.
(If key information is accessible easily, we can check with a specific key.)

Jan 20 2026, 6:06 AM · gnupg26, CVE, TPM, Bug Report
gniibe created T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT`.
Jan 20 2026, 1:54 AM · gnupg26, CVE, TPM, Bug Report
gniibe added projects to T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM: gpgagent, gnupg.
Jan 20 2026, 1:52 AM · CVE, gnupg26, gpgagent, Bug Report
gniibe created T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM.
Jan 20 2026, 1:52 AM · CVE, gnupg26, gpgagent, Bug Report

Jan 19 2026

ikloecker claimed T7789: Kleopatra: Wrong error message when choosing an expired certificate for encryption.
Jan 19 2026, 3:54 PM · vsd34, Bug Report, gpd5x, kleopatra
ikloecker changed the status of T8039: NSIS: Preselection of installed components on reinstall only works with browser integration installed from Open to Testing.

Fixed. The problem was that the selected sections were stored in the 64-bit registry (unless browser integration was installed; see T8038), but they were read from the 32-bit registry.

Jan 19 2026, 3:05 PM · Bug Report, gpd5x, Installer
ikloecker changed the status of T8038: NSIS: Updating line omitted if browser integration is installed from Open to Testing.

Fixed.

Jan 19 2026, 3:03 PM · Bug Report, gpd5x, Installer
ikloecker triaged T8038: NSIS: Updating line omitted if browser integration is installed as Normal priority.

Let's give this Normal priority.

Jan 19 2026, 2:23 PM · Bug Report, gpd5x, Installer
ikloecker claimed T8038: NSIS: Updating line omitted if browser integration is installed.
Jan 19 2026, 2:21 PM · Bug Report, gpd5x, Installer