{"id":"GHSA-9rmp-2568-59rv","summary":"rPGP Panics on Malformed Untrusted Input","details":"During a security audit, [Radically Open Security](https://www.radicallyopensecurity.com/) discovered several reachable edge cases which allow an attacker to trigger `rpgp` crashes by providing crafted data.\n\n### Impact\nWhen processing malformed input, `rpgp` can run into Rust panics which halt the program.\n\nThis can happen in the following scenarios:\n* Parsing OpenPGP messages from binary or armor format\n* Decrypting OpenPGP messages via `decrypt_with_password()`\n* Parsing or converting public keys\n* Parsing signed cleartext messages from armor format\n* Using malformed private keys to sign or encrypt\n\nGiven the affected components, we consider most attack vectors to be reachable by remote attackers during typical use cases of the `rpgp` library. The attack complexity is low since the malformed messages are generic, short, and require no victim-specific knowledge.\n\nThe result is a denial-of-service impact via program termination. There is no impact to confidentiality or integrity security properties.\n\n### Versions and Patches\nAll recent versions are affected by at least some of the above mentioned issues. \n\nThe vulnerabilities have been fixed with version `0.14.1`. We recommend all users to upgrade to this version.\n\n### References\n\n\nThe security audit was made possible by the [NLnet Foundation NGI Zero Core](https://nlnet.nl/core/) grant program [for rpgp](https://nlnet.nl/project/rPGP-cryptorefresh/).","aliases":["CVE-2024-53856","RUSTSEC-2024-0447"],"modified":"2025-12-26T17:38:33.900409Z","published":"2024-12-05T17:30:52Z","database_specific":{"github_reviewed_at":"2024-12-05T17:30:52Z","nvd_published_at":"2024-12-05T16:15:26Z","cwe_ids":["CWE-130","CWE-248","CWE-617"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rpgp/rpgp/security/advisories/GHSA-9rmp-2568-59rv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53856"},{"type":"PACKAGE","url":"https://github.com/rpgp/rpgp"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0447.html"}],"affected":[{"package":{"name":"pgp","ecosystem":"crates.io","purl":"pkg:cargo/pgp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.14.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-9rmp-2568-59rv/GHSA-9rmp-2568-59rv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}