GnuPG Releases Patch Fixing Remote RCE

GnuPG released version 2.5.17 on January 27, 2026 to address a stack buffer overflow in gpg-agent PKDECRYPT (KEM) that can enable remote code execution. The flaw, tracked as T8044 and reported by OpenAI Security Research on January 18, affects GnuPG 2.5.13–2.5.16 and several Gpg4win 5.0.0 builds; Gpg4win 5.0.1 also includes the fix. Users should update immediately or remove gpgsm to mitigate risk.
Scoring Rationale
High urgency and official fix by upstream; limited scope to specific GnuPG/Gpg4win 2.5.x and 5.0.0 builds.
Practice with real FinTech & Trading data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all FinTech & Trading problems


