Description_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs981370

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libgcrypt20 (PTS)buster1.8.4-5+deb10u1fixed
bookworm, sid1.10.1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libgcrypt20source(unstable)(not affected)


- libgcrypt20 <not-affected> (Only affected 1.9)
Introduced by:;a=commit;h=e76617cbab018dd8f41fd6b4ec6740b5303f7e13
Fixed by:;a=commit;h=512c0c75276949f13b6373b5c04f7065af750b08

Search for package or bug name: Reporting problems