---
id: CVE-2026-41989
title: >-
  Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH
  ciphertext (CVE-2026-41989)
summary: >-
  A flaw was found in Libgcrypt. A remote attacker could exploit this
  vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH)
  ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based
  buffer overflow, potentia…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-131
  - CWE-787
vendor: Red Hat
product: Red Hat Enterprise Linux BaseOS (v. 8)
affected:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - insights_proxy 1.5
  - update_infrastructure 5
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_eus_extension_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - insights_proxy 1.5
  - update_infrastructure 5
published: '2026-04-23'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T22:28:41+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41989.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-41989'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2461063'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-41989'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41989'
  - url: 'https://dev.gnupg.org/T8211'
  - url: 'https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html'
  - url: 'https://www.openwall.com/lists/oss-security/2026/04/21/1'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50144'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50147'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52951'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47117'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58978'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58977'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52953'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52952'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52950'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54760'
  - url: 'https://access.redhat.com/errata/RHSA-2026:8466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53371'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00192
epssPercentile: 0.07823
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-23T15:58:58.277481Z'
scores:
  vendor: 7.5
  cna: 6.7
ingestedAt: '2026-09-08T15:33:26.989Z'
---

## Overview

A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.

## Vendor advisories

- **RHSA-2026:50144** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50144)
- **RHSA-2026:50147** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50147)
- **RHSA-2026:52951** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS EUS (v. 10.0) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52951)
- **RHSA-2026:47117** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:47117)
- **RHSA-2026:58979** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58979)
- **RHSA-2026:58978** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58978)
- **RHSA-2026:58977** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58977)
- **RHSA-2026:52953** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52953)
- **RHSA-2026:52952** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.9.4) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52952)
- **RHSA-2026:52950** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS EUS (v.9.6) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52950)
- **RHSA-2026:54760** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54760)

**Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext** — rated Moderate by Red Hat. Released 2026-04-23, updated 2026-09-21.

Fixed:

- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux BaseOS E4S (v.8.8)
- Red Hat Enterprise Linux BaseOS TUS (v.8.8)
- Red Hat Enterprise Linux BaseOS E4S (v.9.2)
- Red Hat Enterprise Linux BaseOS E4S (v.9.4)
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Discovery 2
- Red Hat Hardened Images
- Red Hat Insights proxy 1.5
- Red Hat Update Infrastructure 5

Not affected:

- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS AUS (v.8.4)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux BaseOS E4S (v.8.8)

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:50144
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:50147
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:52951

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
