CVE-2024-58261

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2025
Last modified:
06/08/2025

Description

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:* 1.13.0 (including) 1.21.0 (excluding)