Medium severity6.7NVD Advisory· Published Apr 23, 2026· Updated Jul 14, 2026
CVE-2026-41989
CVE-2026-41989
Description
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <1.12.2
- osv-coords3 versionspkg:rpm/almalinux/libgcryptpkg:rpm/almalinux/libgcrypt-develpkg:rpm/opensuse/libgcrypt&distro=openSUSE%20Leap%2016.0
< 1.8.5-8.el8_10+ 2 more
- (no CPE)range: < 1.8.5-8.el8_10
- (no CPE)range: < 1.8.5-8.el8_10
- (no CPE)range: < 1.12.1-160000.3.1
Patches
Vulnerability mechanics
References
5- lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2026/04/21/1nvdThird Party Advisory
- dev.gnupg.org/T8211nvdBroken Link
- cert-portal.siemens.com/productcert/html/ssa-019113.htmlnvd
- cert-portal.siemens.com/productcert/html/ssa-082556.htmlnvd
News mentions
1- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPCISA ICS Advisories