Re: Bug#1141483: trixie-pu: package gnupg2/2.4.7-21+deb13u2

Andreas Metzler <[email protected]>
Newsgroups gmane.linux.debian.devel.boot
Message-ID <[email protected]>
On 2026-07-13 Jonathan Wiltshire <[email protected]> wrote:
> Control: tag -1 confirmed

> Hi,

> d-i ack needed for the udeb but as far as I'm concerned please go ahead.

I would like to amend this and add the fix for CVE-2026-24882, too.

cu Andreas
2.4.7-21+deb13u2.v2.diff (text/x-diff, 8 KB)
diff --git a/debian/changelog b/debian/changelog
index 786180728..bee79ca42 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,14 @@
+gnupg2 (2.4.7-21+deb13u2) trixie; urgency=medium
+
+  * Fix CVE-2026-57062.
+    CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through
+    2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is
+    supposed to be 12 bytes but 4 bytes is accepted.
+  * Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon during
+    handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
+
+ -- Andreas Metzler <[email protected]>  Sat, 15 Aug 2026 13:40:37 +0200
+
 gnupg2 (2.4.7-21+deb13u1) trixie; urgency=high
 
   * Avoid potential downgrade to SHA1 in 3rd party key signatures.
diff --git a/debian/patches/freepg/0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch b/debian/patches/freepg/0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch
new file mode 100644
index 000000000..dc952def2
--- /dev/null
+++ b/debian/patches/freepg/0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch
@@ -0,0 +1,65 @@
+From 01c130031806010f4c563694501e8739f1580228 Mon Sep 17 00:00:00 2001
+From: Werner Koch <[email protected]>
+Date: Mon, 26 Jan 2026 11:13:44 +0100
+Subject: tpm: Fix possible buffer overflow in PKDECRYPT
+
+* tpm2d/tpm2.c (tpm2_ecc_decrypt): Bail out on too long CIPHERTEXT.
+(tpm2_rsa_decrypt): Ditto.
+--
+
+Cherry pick master commit of:
+	93fa34d9a346020355cd51d54102d30d4f177323
+
+GnuPG-bug-id: 8045
+Co-authored-by: NIIBE Yutaka <[email protected]>
+Reported-by: OpenAI Security Research
+---
+ tpm2d/tpm2.c | 22 +++++++++++++++++++++-
+ 1 file changed, 21 insertions(+), 1 deletion(-)
+
+diff --git a/tpm2d/tpm2.c b/tpm2d/tpm2.c
+index 3e908ddb1..cd0347c6e 100644
+--- a/tpm2d/tpm2.c
++++ b/tpm2d/tpm2.c
+@@ -917,10 +917,20 @@ tpm2_ecc_decrypt (ctrl_t ctrl, TSS_CONTEXT *tssc, TPM_HANDLE key,
+   size_t len;
+   int ret;
+ 
++#if defined(TPM2_MAX_ECC_KEY_BYTES) /* Intel stack */
++  if (ciphertext_len > 2*TPM2_MAX_ECC_KEY_BYTES + 1)
++    return GPG_ERR_TOO_LARGE;
++#elif defined(MAX_ECC_KEY_BYTES)    /* IBM stack */
++  if (ciphertext_len > 2*MAX_ECC_KEY_BYTES + 1)
++    return GPG_ERR_TOO_LARGE;
++#else
++# error TMP2 header are not correctly installed
++#endif
++
+   /* This isn't really a decryption per se.  The ciphertext actually
+    * contains an EC Point which we must multiply by the private key number.
+    *
+-   * The reason is to generate a diffe helman agreement on a shared
++   * The reason is to generate a diffie-hellman agreement on a shared
+    * point.  This shared point is then used to generate the per
+    * session encryption key.
+    */
+@@ -976,6 +986,16 @@ tpm2_rsa_decrypt (ctrl_t ctrl, TSS_CONTEXT *tssc, TPM_HANDLE key,
+   TPM_HANDLE ah;
+   char *auth;
+ 
++#if defined(TPM2_MAX_RSA_KEY_BYTES)  /* Intel stack */
++  if (ciphertext_len > TPM2_MAX_RSA_KEY_BYTES)
++    return GPG_ERR_TOO_LARGE;
++#elif defined(MAX_RSA_KEY_BYTES)     /* IBM stack */
++  if (ciphertext_len > MAX_RSA_KEY_BYTES)
++    return GPG_ERR_TOO_LARGE;
++#else
++# error TMP2 header are not correctly installed
++#endif
++
+   inScheme.scheme = TPM_ALG_RSAES;
+   /*
+    * apparent gcrypt error: occasionally rsa ciphertext will
+-- 
+2.39.5
+
diff --git a/debian/patches/freepg/0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch b/debian/patches/freepg/0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch
new file mode 100644
index 000000000..2277dcee3
--- /dev/null
+++ b/debian/patches/freepg/0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch
@@ -0,0 +1,42 @@
+From 555a9f5b3a0ca69e663373d47902e0bec0bd49d0 Mon Sep 17 00:00:00 2001
+From: NIIBE Yutaka <[email protected]>
+Date: Thu, 12 Feb 2026 11:51:17 +0900
+Subject: agent: Fix the regression in pkdecrypt with TPM RSA.
+
+* agent/divert-tpm2.c (divert_tpm2_pkdecrypt): Care about additional
+0x00.
+
+--
+
+Cherry pick master commit of:
+	6eed3959303c81c9699fe9273030e480732f72be
+
+GnuPG-bug-id: 8045
+Signed-off-by: NIIBE Yutaka <[email protected]>
+---
+ agent/divert-tpm2.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+diff --git a/agent/divert-tpm2.c b/agent/divert-tpm2.c
+index 2496d091a..5b5bd14bb 100644
+--- a/agent/divert-tpm2.c
++++ b/agent/divert-tpm2.c
+@@ -135,6 +135,15 @@ divert_tpm2_pkdecrypt (ctrl_t ctrl,
+       if (!smatch (&s, n, "a"))
+         return gpg_error (GPG_ERR_UNKNOWN_SEXP);
+       n = snext (&s);
++      /* NOTE: gpg-agent protocol uses signed integer for RSA (%m in
++       * MPI), where 0x00 is added when the MSB is 1.  TPM2 uses
++       * unsigned integer.  We need to remove this 0x00, or else
++       * it may result GPG_ERR_TOO_LARGE in tpm2daemon.  */
++      if (!*s && (n&1))
++        {
++          s++;
++          n--;
++        }
+     }
+   else if (smatch (&s, n, "ecdh"))
+     {
+-- 
+2.39.5
+
diff --git a/debian/patches/from-master/0004-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch b/debian/patches/from-master/0004-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch
new file mode 100644
index 000000000..be629b0ee
--- /dev/null
+++ b/debian/patches/from-master/0004-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch
@@ -0,0 +1,45 @@
+From 4c7e68cf3d335328821bdbb70db309a60d0e4fd4 Mon Sep 17 00:00:00 2001
+From: Werner Koch <[email protected]>
+Date: Thu, 18 Jun 2026 10:51:34 +0200
+Subject: [PATCH] gpgsm: Require a minimum tag length for GCM decryption.
+
+* sm/decrypt.c (gpgsm_decrypt): Require a minimum authtaglen.
+--
+
+Reported-by: Thai Duong <[email protected]>
+CVE-id: CVE-2026-57062
+---
+ sm/decrypt.c | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/sm/decrypt.c b/sm/decrypt.c
+index 20fb96060..92a33c6e6 100644
+--- a/sm/decrypt.c
++++ b/sm/decrypt.c
+@@ -1443,15 +1443,22 @@ gpgsm_decrypt (ctrl_t ctrl, estream_t in_fp, estream_t out_fp)
+               if (rc)
+                 {
+                   log_error ("error getting authtag: %s\n", gpg_strerror (rc));
+                   goto leave;
+                 }
+               if (DBG_CRYPTO)
+                 log_printhex (authtag, authtaglen, "Authtag ...:");
+-              rc = gcry_cipher_checktag (dfparm.hd, authtag, authtaglen);
++              if (authtaglen < 12)
++                {
++                  log_info ("authentication tag is too short (%zu octets)\n",
++                            authtaglen);
++                  rc = gpg_error (GPG_ERR_CHECKSUM);
++                }
++              else
++                rc = gcry_cipher_checktag (dfparm.hd, authtag, authtaglen);
+               xfree (authtag);
+               if (rc)
+                 log_error ("data is not authentic: %s\n", gpg_strerror (rc));
+               goto leave;
+             }
+         }
+     }
+-- 
+2.53.0
+
diff --git a/debian/patches/series b/debian/patches/series
index 3b42e1375..870ea4e34 100644
--- a/debian/patches/series
+++ b/debian/patches/series
@@ -20,6 +20,8 @@ freepg/0026-gpg-Default-to-compliance-openpgp.patch
 freepg/0029-Add-keyboxd-systemd-support.patch
 freepg/0033-Support-large-RSA-keygen-in-non-batch-mode.patch
 freepg/0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch
+freepg/0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch
+freepg/0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch
 debian-packaging/avoid-beta-warning.patch
 debian-packaging/avoid-regenerating-defsincdate-use-shipped-file.patch
 dirmngr-idling/dirmngr-hkp-Avoid-potential-race-condition-when-some.patch
@@ -36,6 +38,7 @@ from-master/gpg-agent-idling/0007-agent-Fix-the-previous-commit.patch
 from-master/gpg-agent-idling/0008-agent-Fix-timer-list-management.patch
 from-master/gpg-agent-idling/0009-agent-Fix-sock_inotify_fd-handling.patch
 from-master/gpg-agent-idling/0010-agent-Fix-timer-round-up-check-when-inserting-an-ent.patch
+from-master/0004-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch
 Use-hkps-keys.openpgp.org-as-the-default-keyserver.patch
 debian-packaging/Build-regexp-against-debian-s-unicode-data-package.patch
 debian-packaging/Always-build-common-status-codes.h-and-common-audit-event.patch
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmqAUh8ACgkQpU8BhUOC
FIQKJw//fcWDuOHWt9M9jj11xRVKH3qM+6MY8HUtlckTvdh2QqSS45iOjKjR1zKG
oDfoStfSZArmUAFWol1CuWsYdAQWVkVeU20s7HAYTMxlqOH2m8t1+KSHxZW0RIGt
dPsJWWwgAYQ78ZxPBGxFmKUIf5q34SSXDzkGy4UxcLxcd0/h3rHaUr0AMujO4Glt
QA+0sljibi5cM0W6iXY9XY42FsO5JF4okic0V60i2hizAkkekzs32i0+lU2ExQ/v
sQeG4xV/o/+EhyMMDR03Hftp1yzt9kVlBJXwmxYI9/4D6guRVzkfZFnSTrGJofJk
HcI+nRLMXhEIUDxl4p7h/DxKoFR84sZUYQro+UCu6TGnCOKzXoW0ueZSjmrRr46e
L4SwryNS24QkKPAQ5WgzUbeftTIqdo6ACJ8HAxKz4RC0QXI3AmLzsHzcwQq3enc5
nCbEb51PcMU1dNoRmOprhTPJostJ/jpysRN0XgDRWWU8KvJUbjcF6Bw5yFT2Gjm5
TpT5M5UQ7xeeuzSlR7nNHhEaUhprGezuuXqVCTgOUEqVnkdsp+SoVLgU3nXWmH2V
grfhHlwoIMyIUsJMAo79HN3ECmkpLijoOvFygpfsQllJvV8vLQGJaOYMSAgqwDZS
qIS21TeZSfcPxYGY3hzUWxFGFDdTlsnZlScnv6xtaijJhMcOzzs=
=RqHs
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.