I found two issues in libgpg-error for spawning functions.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed Advanced Search
Advanced Search
Advanced Search
Wed, Feb 4
Wed, Feb 4
Mon, Feb 2
Mon, Feb 2
Oh yeah, the mentioned patch is bogus because it assumes that fgets has already set the eof flag while reading the last line. This seems not to be the case.
Fri, Jan 30
Fri, Jan 30
I added the gpgsm log output (same error as in the gpg log)
Tue, Jan 27
Tue, Jan 27
• ebo moved T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Backlog to Done on the gnupg26 board.
Mon, Jan 26
Mon, Jan 26
To reproduce the hang, a loop will suffice (usually happens within the first 15 times, once it needed 50 runs):
Fri, Jan 23
Fri, Jan 23
Wed, Jan 21
Wed, Jan 21
• werner shifted T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from the Restricted Space space to the S1 Public space.
• werner changed the status of T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Open to Testing.
Tue, Jan 20
Tue, Jan 20
I have this fix committed to my working directory:
We have no CVE yet. However, CVE is also a good tag for security bugs,
• werner renamed T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM from Security (internal) - gpg-agent stack buffer overflow to gpg-agent stack buffer overflow in pkdecrypt using KEM.
On 2026-01-20, I found the message to security@gnupg.org of:
Message-ID: 4e708880-04ac-45bc-8d16-6b585f2652a1n@aisle.com
in may spam folder. It has a 10MB long attachment. That might be one of reasons to be identified as a spam.
• gniibe added projects to T8044: gpg-agent stack buffer overflow in pkdecrypt using KEM: gpgagent, gnupg.
Jan 13 2026
Jan 13 2026
• ebo edited projects for T7799: gpg-agent crashes when using putty for ssh connection, added: gpd5x (gpd-5.0.0); removed gpd5x.
Jan 9 2026
Jan 9 2026
• ebo closed T7491: Confusing additional pinentry on creation of new keypair with ADSK configured as Resolved.
This does not happen any more, tested with Gpg4win-5.0.0-beta479