Re: libgcrypt P256 signature malleability via weak DER enforcement

Sam James via Gnupg-devel <[email protected]> Wed, 14 Jan 2026 22:43:33 +0000
Newsgroups gmane.comp.encryption.gpg.devel
Organization Gentoo
Message-ID <[email protected]>
Jake Ginesin via Gnupg-devel <[email protected]> writes:

> Thank you for your response, and thank you for upstreaming this issue to libksba. 
>
> May I be granted a GNU bugtracker account, such that I may participate in the ticket thread? I would like to emphasize
> the security impact of this issue, as an attacker may very trivially mutate signatures without affecting validity. In
> addition to the CVEs previously mentioned, CVE-2019-14859 and BIP-66 also report on the same issue in other libraries. 

As a casual observer, is there a reason you submitted this publicly, and
not via https://gnupg.org/documentation/security.html?

I'm a bit surprised to have seen it publicly and also found it strange
someone else did something similar recently on the libgcrypt mailing list.

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc (application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE-----

iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmloHBUbFIAAAAAABAAO
bWFudTIsMi41KzEuMTEsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z
Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx
QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkIJu
AQDXGoAdZaaJZi5qhKiP7WZxs3j1NWIy3g26aSQ/gmd31QEA98086SAFaCwcfd18
aZGAAiLbUcu6un0n0ACIvkYO+wU=
=BEq/
-----END PGP SIGNATURE-----