Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
Moderate severity
GitHub Reviewed
Published
Dec 14, 2025
to the GitHub Advisory Database
•
Updated Dec 16, 2025
Description
Published by the National Vulnerability Database
Dec 14, 2025
Published to the GitHub Advisory Database
Dec 14, 2025
Reviewed
Dec 16, 2025
Last updated
Dec 16, 2025
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
References