Description_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
NVD severityhigh
Debian Bugs981370

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libgcrypt20 (PTS)stretch1.7.6-2+deb9u3fixed
stretch (security)1.7.6-2+deb9u4fixed
bullseye, sid1.8.7-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libgcrypt20source(unstable)(not affected)


- libgcrypt20 <not-affected> (Only affected 1.9)
Introduced by:;a=commit;h=e76617cbab018dd8f41fd6b4ec6740b5303f7e13
Fixed by:;a=commit;h=512c0c75276949f13b6373b5c04f7065af750b08

