CVE-2026-24883 | GnuPG up to 2.5.16 Signature Packet Length parse_signature null pointer dereference (Nessus ID 296934 / WID-SEC-2026-0231)
A vulnerability, which was classified as problematic, has been found in GnuPG up to 2.5.16. This vulnerability affects the function parse_signature of the component Signature Packet Length Handler. Performing a manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2026-24883. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.